Fortra published a critical stack buffer overflow in Core Privileged Access Manager (BoKS) on October 1. A remote attacker who can reach the autoregistration service may corrupt memory during client response handling — the kind of PAM control-plane bug you want closed before someone maps port 6507 from the wrong network.
Fixed builds are out. If you run BoKS, Friday is a good day to confirm who owns the servers, whether autoregistration is even needed, and that nothing is listening for strangers.
Privileged access management is the keys to the kingdom. Leave the autoregistration door unlocked and the kingdom finds you.
The 5-Minute Cyber BriefDon’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
What happened
Fortra advisory FI-2026-017 covers CVE-2026-12627 in boks_autoregisterd. The service contains a stack-based buffer overflow (CWE-121). A remote attacker with network access to the autoregistration listener can trigger memory corruption while the daemon processes a client response. Fortra rates it critical (CVSS 9.8: network, low complexity, no privileges, no user interaction).
Affected versions: BoKS 8.1.0.0 through 8.1.0.23 and 9.0.0.0 through 9.0.0.6. Fixed packages: boks-server 8.1.0.24 and 9.0.0.7. The default listener is port 6507. Discovery was August 25, 2026; public advisory October 1, 2026. No public PoC was indexed at disclosure, and the CVE is not on KEV as of publish time.
Why it matters
BoKS is privileged access management. A remote memory-corruption bug on an autoregistration daemon is not a user-facing inconvenience — it is a path toward the systems that mint and broker elevated sessions. Even without a public exploit yet, internet-exposed or flat-network access to port 6507 is an unacceptable blast radius.
What to do first
- Inventory BoKS servers. Identify hosts on 8.1.x and 9.0.x and note whether
boks_autoregisterdis running. - Upgrade. Move to boks-server 8.1.0.24 or 9.0.0.7 per FI-2026-017.
- Restrict or disable the listener. Until patched, allow port 6507 only from trusted management / registration clients. If autoregistration is unused, stop and disable
boks_autoregisterd. - Confirm exposure. Check firewall, cloud security groups, and internal flat networks for unexpected reachability to 6507/tcp.
Forward this
If you own privileged access / BoKS: Fortra released a critical remote overflow in the autoregistration service (CVE-2026-12627). Please confirm every BoKS server is on 8.1.0.24 or 9.0.0.7, that port 6507 is not reachable from untrusted networks, and that unused autoregistration is disabled.
Details
- CVE: CVE-2026-12627 (BoKS
boks_autoregisterdstack buffer overflow) - Impact: Remote memory corruption via crafted client responses to the autoregistration service
- CVSS: 9.8 (Fortra)
- Advisory: FI-2026-017 (Oct 1, 2026)
- Affected: 8.1.0.0–8.1.0.23; 9.0.0.0–9.0.0.6
- Fixed: boks-server 8.1.0.24 / 9.0.0.7
- Default port: 6507/tcp
- Workaround: Restrict access to the service; disable if autoregistration is not required
Hunt / verify
- Confirm package version ≥ 8.1.0.24 or ≥ 9.0.0.7 on every BoKS server.
- Verify listeners: nothing unexpected on 6507 from non-management sources.
- Review recent autoregistration events and BoKS audit logs for anomalous clients.
Slack paste: Fortra BoKS CVE-2026-12627 critical overflow in boks_autoregisterd — upgrade to 8.1.0.24 / 9.0.0.7, lock down or disable port 6507.
Sources
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.