Fortra Core Privileged Access Manager Server — known CVE vulnerabilities
Every CVE whose affected-product data names Fortra Core Privileged Access Manager Server, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (2)
CVE-2026-9862 — CVSS 9.8 (critical): Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote…
CVE-2026-9863 — CVSS 7.5 (high): Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client…