CVE-2026-9864

Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Directory join or password renewal operations may have significantly less entropy than intended, making them more susceptible to prediction by an attacker who can estimate when the password was generated.

  • Published Oct 1, 2026
  • CVSS 4.8 medium
  • 0.1% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-9864 at the National Vulnerability Database