CVE-2026-12627

Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing.

  • Published Oct 1, 2026
  • CVSS 9.8 critical
  • 0.4% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-12627 at the National Vulnerability Database