Fortra security advisory (AV26-987)

Canadian Centre for Cyber Security Version 2 imported change current

Imported from official source

Serial number: AV26-987Date: October 2, 2026 As of October 1, 2026, Fortra is affected by a vulnerabilities in the following product: BoKS Manager boks-server Prior to 8.1.0.24 Prior to 9.0.0.7 BoKS Manager Prior to 8.1.0.24 Prior to 9.0.0.7 Core Privileged Access Manager (BoKS) Prior to 10.1.1.0 Prior to 9.0.0.7 Prior to 8.1.0.30 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Heap overflow in KSL checksum initialization Fortra's Core Privileged Access Manager (BoKS) autoregistration stack buffer overflow vulnerability Heap buffer overflow in boks_sshd revoked-key error handling Fortra BoKS Manager boks_portmux TLS ClientHello out-of-bounds read vulnerability Product Security Advisories | Fortra

This version

Version
2 of 2
Recorded
October 02, 2026 15:00
Change
Imported change
Content hash
11b3a9b0166a772d0ae79793a51321c6
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.