CVE-2026-9862Disclosure(fortra / core_privileged_access_manager_server)
MEDIUMCVSS 9.8 · CRITICALExploitation ongoing with high activity in latest observed window (1 mentions)
Immediate actions
- Patch fortra core_privileged_access_manager_server systems immediately
- Assume compromise if assets are exposed
Recommended action window: Immediate (within 24h)
NVD description
Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.
4.0/ 10 priority
Sources & remediation
Vendor / third-party advisories
Weakness type (CWE)
CWE-78
Priority
MEDIUM
Exploitation
ACTIVE
PoC
NONE
Patch
AVAILABLE
Momentum
STABLE
Are you affected?
If you run products in this scope, you should treat this CVE as relevant to your environment.
- core_privileged_access_manager_server
Threat summary
- Active exploitation appears in 1 classified signals
- Patch or workaround signal is available
- 6 mentions across 4 observed days
- Momentum state: stable
What's happening
- Active exploitation reported across 1 signal
- Patch or workaround mentioned in 2 signals
- Technical details provided in 4 signals
- Disclosure: 3 classified signals
- General: 2 classified signals
- Peaked 3d ago at 2 mentions (2026-06-15); latest day: 1
- 6 total mentions across 4 days
Affected systems
Vendors
Products
core_privileged_access_manager_server
Deep dive
Activity timeline6 mentions / 4d
Signal classification3 categories
Disclosure350.0%
General233.3%
Active Exploitation116.7%
Referenced assets4 URLs
Classification over time
| Date | Total | Labels |
|---|
| 2026-06-15 | 2 | Active Exploitation1General1 |
| 2026-06-16 | 1 | General1 |
| 2026-06-17 | 2 | Disclosure2 |
| 2026-06-19 | 1 | Disclosure1 |
CPE platform detail1 entries
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | fortra | core_privileged_access_manager_server | - | - | - |
