Threat Overview
Fortra published eight Core Privileged Access Manager (BoKS) advisories on October 1, 2026, including three critical vulnerabilities spanning identity, privileged command execution, and unauthenticated memory corruption. CVE-2026-79901 (CVSS 9.9) affects deployments using BoKS keytab management for Active Directory service accounts: boks_keytabmd generates passwords from a predictable sequence seeded with the Unix timestamp, allowing an attacker who knows the service principal and approximates the change time to derive a small candidate set and verify it offline with Kerberos ticket material. A standard authenticated AD user can normally request the required service ticket.
CVE-2026-79898 (CVSS 9.1) is command injection in crlserver. An authenticated BoKS user authorized to add CRL URLs through BCC, WSI REST/SOAP, or cacrl can cause shell command substitution to execute as root on the BoKS Master. CVE-2026-12627 (CVSS 9.8) is a stack buffer overflow in boks_autoregisterd; a remote attacker with network access to the autoregistration service may trigger memory corruption during client response processing.
Fortra and subsequent reporting did not identify in-the-wild exploitation as of October 5. No public exploit syntax or IOCs were supplied. The hunt therefore emphasizes affected BoKS inventory, crlserver child processes, suspicious CRL administration, autoregistration crashes, access to the default autoregistration port, AD/Kerberos activity involving BoKS-managed service accounts, and root-level persistence on BoKS Masters.
References
- Fortra FI-2026-012, “Predictable Active Directory service-account passwords in BoKS Manager,” published October 1, 2026: https://www.fortra.com/security/advisories/product-security/fi-2026-012
- Fortra FI-2026-015, “Fortra BoKS Manager crlserver command injection vulnerability,” published October 1, 2026: https://www.fortra.com/security/advisories/product-security/fi-2026-015
- Fortra FI-2026-017, “Core Privileged Access Manager (BoKS) autoregistration stack buffer overflow vulnerability,” published October 1, 2026: https://www.fortra.com/security/advisories/product-security/fi-2026-017
- Canadian Centre for Cyber Security, “Fortra security advisory (AV26-987),” published October 1, 2026: https://www.cyber.gc.ca/en/alerts-advisories/fortra-security-advisory-av26-987
- SecurityWeek, “Fortra Patches Critical Vulnerabilities in BoKS,” published October 3, 2026: https://www.securityweek.com/fortra-patches-critical-vulnerabilities-in-boks/
Impacted Systems
- Vendor/product: Fortra Core Privileged Access Manager (BoKS), including BoKS Manager/Master services.
- Affected builds: BoKS Manager
boks-serverbefore 8.1.0.24 and before 9.0.0.7 for the October advisory set. The CVE record for CVE-2026-79901 identifiesboks-serverversions before 9.0.0.6; use 9.0.0.7 as the operational remediation target for the full cluster. - Fixed builds:
boks-server8.1.0.24 or 9.0.0.7, as applicable to the supported branch. - Platform/deployment: Self-managed Unix/Linux privileged-access infrastructure; BoKS Master is the central trust and policy-management role.
- CVE-2026-79901 prerequisite: BoKS keytab management is used for AD service accounts; attacker knows the SPN, approximates password-change time, and has Kerberos service-ticket material. Deployments not using BoKS keytab management and administrator-supplied initial passwords are not affected by this code path.
- CVE-2026-79898 prerequisite: Authenticated user with permission to add CRL URLs via network-accessible BCC/WSI or local
cacrl; injected substitution runs as root on the Master. - CVE-2026-12627 prerequisite/exposure: Network access to
boks_autoregisterd, which listens on TCP 6507 by default; authentication is not required according to the CVSS vector.
Why this matters
BoKS centralizes privileged access across Unix/Linux fleets and may manage AD service-account secrets. Compromise of the Master can cross operating-system and identity boundaries. The cluster offers three materially different paths—offline recovery of managed credentials, authorized-user-to-root command injection, and unauthenticated memory corruption—so a single IOC query would provide inadequate coverage.
Exploitation Status
No confirmed in-the-wild exploitation was identified in the cited sources as of October 5, 2026. The vulnerabilities and exploit preconditions are vendor-confirmed. No public payload, attacker infrastructure, malware hash, or validated intrusion chain was published. Behavioral results should be treated as leads requiring BoKS and identity context, not proof that a specific CVE was exploited.
What this hunt looks for
BoKS services and versions, crlserver child processes, command-substitution characters in CRL administration, boks_autoregisterd crashes, concentrated or rare TCP/6507 sources, Kerberos activity for confirmed BoKS-managed SPNs, service-account password changes, and root persistence.
Required logs
BoKS and Unix/Linux Syslog or audit data; Microsoft Defender for Endpoint DeviceProcessEvents and DeviceFileEvents on the BoKS Master; firewall or flow telemetry in CommonSecurityLog for TCP/6507 and management paths; and domain-controller SecurityEvent data for Kerberos and service-account changes.
Hunt 1 — First-pass BoKS process and package inventory
let lookback = 14d;
union isfuzzy=true
(
DeviceProcessEvents
| where Timestamp >= ago(lookback)
| where FileName startswith "boks_" or FileName in~ ("crlserver", "cacrl", "bcc") or FolderPath has_any ("/boks/", "/BoKS/")
| project TimeGenerated=Timestamp, Computer=DeviceName, Source="MDE", Detail=strcat(FolderPath, "/", FileName, " ", ProcessCommandLine)
),
(
Syslog
| where TimeGenerated >= ago(lookback)
| where ProcessName startswith "boks" or ProcessName in~ ("crlserver", "cacrl") or SyslogMessage has_any ("boks-server", "boks_autoregisterd", "boks_keytabmd")
| project TimeGenerated, Computer, Source="Syslog", Detail=strcat(ProcessName, ": ", SyslogMessage)
)
| summarize FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), Evidence=make_set(Detail, 20), Sources=make_set(Source, 5) by Computer
| order by LastSeen desc
Hunt 2 — crlserver spawning a shell or network utility
let lookback = 30d;
DeviceProcessEvents
| where Timestamp >= ago(lookback)
| where InitiatingProcessFileName =~ "crlserver" or InitiatingProcessCommandLine has "crlserver"
| where FileName in~ ("sh", "bash", "dash", "ksh", "zsh", "curl", "wget", "nc", "ncat", "socat", "python", "python3", "perl")
| project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine, SHA256, InitiatingProcessFileName, InitiatingProcessCommandLine
| order by Timestamp desc
Hunt 3 — Suspicious CRL URL administration in BoKS logs
let lookback = 30d;
Syslog
| where TimeGenerated >= ago(lookback)
| where ProcessName has_any ("crlserver", "cacrl", "bcc", "wsi") or SyslogMessage has_any ("CRL URL", "cacrl", "crlserver")
| where SyslogMessage has_any ("$(", "`", ";", "|", "&&", "${", "/bin/sh", "/bin/bash", "curl ", "wget ")
| project TimeGenerated, Computer, Facility, SeverityLevel, ProcessName, SyslogMessage
| order by TimeGenerated desc
Hunt 4 — boks_autoregisterd crash or memory-fault signals
let lookback = 30d;
Syslog
| where TimeGenerated >= ago(lookback)
| where ProcessName has "boks_autoregisterd" or SyslogMessage has "boks_autoregisterd"
| where SyslogMessage has_any ("segfault", "segmentation fault", "stack smashing", "buffer overflow", "core dumped", "aborted", "SIGSEGV", "restarted", "respawn")
| project TimeGenerated, Computer, Facility, SeverityLevel, ProcessName, SyslogMessage
| order by TimeGenerated desc
Hunt 5 — Connection concentration to the default autoregistration service
let lookback = 30d;
CommonSecurityLog
| where TimeGenerated >= ago(lookback)
| where DestinationPort == 6507
| summarize Connections=count(), FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), Actions=make_set(DeviceAction, 10), SourcePorts=dcount(SourcePort) by SourceIP, DestinationIP, bin(TimeGenerated, 10m)
| where Connections >= 10
| order by Connections desc
Hunt 6 — Rare sources connecting to BoKS TCP 6507
let baseline = 30d;
let recent = 2d;
let Known = CommonSecurityLog
| where TimeGenerated between (ago(baseline) .. ago(recent)) and DestinationPort == 6507
| summarize by SourceIP, DestinationIP;
CommonSecurityLog
| where TimeGenerated >= ago(recent) and DestinationPort == 6507
| join kind=leftanti Known on SourceIP, DestinationIP
| summarize Connections=count(), FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), Actions=make_set(DeviceAction, 10) by SourceIP, DestinationIP
| order by Connections desc
Hunt 7 — Kerberos service-ticket bursts for known BoKS-managed SPNs
let lookback = 30d;
let BoKSManagedSPNs = dynamic(["REPLACE_WITH_CONFIRMED_BOKS_MANAGED_SPN"]);
SecurityEvent
| where TimeGenerated >= ago(lookback) and EventID == 4769
| where ServiceName in~ (BoKSManagedSPNs)
| summarize Tickets=count(), SourceHosts=dcount(WorkstationName), SourceIPs=dcount(IpAddress), EncryptionTypes=make_set(TicketEncryptionType, 10), Failures=countif(Status != "0x0") by Account, ServiceName, bin(TimeGenerated, 30m)
| where Tickets >= 20 or Failures > 0
| order by Tickets desc
Hunt 8 — Password changes affecting confirmed BoKS-managed AD service accounts
let lookback = 30d;
let BoKSManagedAccounts = dynamic(["REPLACE_WITH_CONFIRMED_BOKS_MANAGED_ACCOUNT"]);
SecurityEvent
| where TimeGenerated >= ago(lookback) and EventID in (4723, 4724, 4738)
| where TargetAccount in~ (BoKSManagedAccounts) or TargetUserName in~ (BoKSManagedAccounts)
| project TimeGenerated, Computer, EventID, SubjectAccount, SubjectUserName, TargetAccount, TargetUserName, Activity
| order by TimeGenerated desc
Hunt 9 — Root persistence changes on a BoKS Master
let lookback = 30d;
DeviceFileEvents
| where Timestamp >= ago(lookback)
| where InitiatingProcessAccountName =~ "root"
| where FolderPath has_any ("/etc/cron", "/etc/systemd/system/", "/usr/lib/systemd/system/", "/root/.ssh/", "/etc/sudoers", "/etc/ld.so.preload")
| where InitiatingProcessFileName in~ ("crlserver", "sh", "bash", "dash", "curl", "wget", "python", "python3") or InitiatingProcessParentFileName =~ "crlserver"
| project Timestamp, DeviceName, ActionType, FolderPath, FileName, SHA256, InitiatingProcessAccountName, InitiatingProcessFileName, InitiatingProcessCommandLine
| order by Timestamp desc
Detection Notes
- Hunt 1 is the required first pass. Confirm package versions with the authoritative package manager or Fortra tooling; process telemetry rarely contains reliable BoKS build numbers.
- Hunt 2 is high signal because
crlservershould not ordinarily spawn an interactive shell or download utility. Endpoint coverage on the Linux Master is required. - Hunt 3 detects generic command-substitution characters in CRL administration logs. URLs can legitimately contain some punctuation, and BCC/WSI may not log the full submitted value; validate against approved CRL endpoints.
- Hunts 4–6 address CVE-2026-12627. A crash is not proof of exploitation, and successful memory corruption may not emit a distinctive message. Restrict the target set to known BoKS Master IPs.
- Hunts 7 and 8 require replacing the explicit placeholders with confirmed BoKS-managed SPNs and accounts. Broad, unscoped Kerberos analytics would be noisy and would not specifically test CVE-2026-79901.
- Offline password candidate testing is not visible in Sentinel. Domain-controller events can show ticket requests and subsequent use, but cannot prove how a password was recovered.
- Missing Linux endpoint telemetry, BoKS/Syslog, firewall flow data, or domain-controller Security Events prevents the relevant exploitation path from being visible in Sentinel.