Critical severity9.8NVD Advisory· Published Jun 15, 2026· Updated Jun 15, 2026
CVE-2026-9862
CVE-2026-9862
Description
Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
2- ⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and MoreThe Hacker News · Jun 22, 2026
- Fortra Access Manager Vulnerability Enables Remote Command Injection AttacksCyber Security News · Jun 17, 2026