PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchFortra published eight BoKS security advisories on October 1, 2026: three Critical, three High, and two Medium. The flaws span password generation, certificate revocation handling, autoregistration, TLS, and other components. Fortra’s October 2 release notes list fixes for several issues in the 8.1 and 9.0 server lines, but a government CERT summary gives a different 8.1 fixed-version threshold. Administrators should check which flaws and components apply to their deployment and confirm the correct package with Fortra before treating any specific 8.1 build as fixed.
What did Fortra patch in BoKS?
The October 1 advisories cover separate flaws in BoKS Manager and related components. Their severity ratings are CVSS v3.1 scores published by Fortra; they indicate vulnerability severity, not a measurement of risk to any particular organization. Access requirements and configuration determine whether a flaw applies to a deployment.
| Fortra advisory and CVE | Severity | Affected component and exposure |
|---|---|---|
| FI-2026-012 CVE-2026-79901 |
Critical CVSS 9.9 |
boks_keytabmd can generate predictable passwords for Active Directory service accounts in deployments using BoKS keytab management. Fortra says exploitation requires knowledge of the affected service principal, an estimate of when its password changed, and suitable Kerberos ticket material. Deployments not using keytab management and accounts initialized with administrator-supplied passwords are not affected by this issue. (Fortra advisory FI-2026-012.) |
| FI-2026-013 CVE-2026-79900 |
Medium CVSS 6.5 |
An authenticated KSL client can supply an oversized recognized digest name to boks_ksllogsd, causing a write beyond a heap allocation. Fortra’s advisory specifies that the updated boks_ksllogsd must be running. (Fortra advisory FI-2026-013.) |
| FI-2026-014 CVE-2026-79899 |
High CVSS 6.5 |
bccgethostcert creates predictable temporary files without a restrictive umask. A local user able to read BOKS_tmp may obtain CA secret or host private-key material. (Fortra advisory FI-2026-014.) |
| FI-2026-015 CVE-2026-79898 |
Critical CVSS 9.1 |
An authenticated user authorized to add CRL URLs can trigger shell command substitution processed by crlserver as root on the BoKS Master. The URL may be added through BCC, WSI REST or SOAP, or cacrl. (Fortra advisory FI-2026-015.) |
| FI-2026-016 CVE-2026-79896 |
High CVSS 7.5 |
A remote unauthenticated attacker can send a malformed TLS ClientHello to boks_portmux and terminate it. Repeated requests may keep the service interruption going. (Fortra advisory FI-2026-016.) |
| FI-2026-017 CVE-2026-12627 |
Critical CVSS 9.8 |
A remote attacker with network access to boks_autoregisterd may trigger memory corruption while the service processes a client response. (Fortra advisory FI-2026-017.) |
| FI-2026-018 CVE-2026-9864 |
Medium CVSS 4.8 |
The adjoin utility may generate machine-account passwords with less entropy than intended during an Active Directory join or password renewal. Predictability may increase for an attacker able to estimate the generation time. (Fortra advisory FI-2026-018.) |
| FI-2026-019 CVE-2026-14316 |
High CVSS 8.1 |
In boks_sshd, the error-handling path for a revoked key formats a failure reason into an undersized heap buffer. (Fortra advisory FI-2026-019.) |
Which vulnerabilities should administrators prioritize?
Prioritize according to actual exposure, not the CVSS score alone. The October advisories describe three different critical scenarios: a password-generation flaw limited to a particular AD keytab configuration, an authenticated command-injection path requiring permission to add CRL URLs, and a remotely reachable autoregistration flaw. Check feature use, account privileges, and network reachability before deciding which systems are exposed.
- Check autoregistration reachability: Identify systems where
boks_autoregisterdis running and determine which networks can reach it. The October stack-overflow advisory describes a remote attacker with network access; it does not state that authentication is required. - Review CRL URL permissions: Find who can add CRL URLs through BCC, WSI REST or SOAP, or
cacrl. The described attack requires an authenticated user who is authorized to perform that action. - Confirm AD keytab use: Determine whether BoKS keytab management generates passwords for the affected AD service accounts. The password flaw does not apply, according to Fortra, to deployments that do not use keytab management or to administrator-supplied initial passwords.
- Assess service availability and local access: Include the remote TLS-triggered
boks_portmuxinterruption, the local-user condition involvingBOKS_tmp, and the other component-specific issues in your exposure review.
Which BoKS versions are affected, and what version fixes the flaws?
Fortra’s BoKS Manager release notes dated October 2, 2026 identify server packages s-8.1.0.24 and s-9.0.0.7. The notes list fixes for the KSL checksum issue, CRL command-injection protection, malformed TLS ClientHello crashes, and an autoregistration proxy version overflow in both server lines. The advisory for FI-2026-013 also specifies the corresponding 8.1.0.24 or 9.0.0.7 server package and requires the updated boks_ksllogsd to be running. (Fortra BoKS Manager release notes, October 2, 2026; Fortra advisory FI-2026-013.)
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errors#1 Best Overall
There is an unresolved conflict for the 8.1 line. A CSIRT Toscana notice published October 2 says 8.1.0.x versions before 8.1.0.30 are affected, while Fortra’s release notes identify s-8.1.0.24. The available notices do not explain the discrepancy. Do not treat 8.1.0.24 as a confirmed safe threshold—or substitute 8.1.0.30 as a vendor-confirmed fix—without clarification from Fortra.
The same CSIRT Toscana notice says 9.0.0.x versions before 9.0.0.7 and 10.1.0.x versions before 10.1.1.0 are affected. Fortra’s cited October release notes identify the 9.0 package but do not establish an October 10.1 package in the material available here. Confirm the applicable maintenance line and current supported packages with Fortra Support.
These release-note entries concern server packages. They do not establish that installing one server package alone remediates every Server Agent condition or applies to every deployment. Ask Fortra to confirm the correct server and agent packages for your installed version and the specific advisories in scope; the published information does not establish a universal installation sequence.
Do I need to update BoKS Manager?
If your installation includes any affected component or configuration, plan remediation using Fortra’s package guidance and confirm the build with the vendor where the 8.1 discrepancy matters. Before scheduling the change, inventory the BoKS version and maintenance line, identify the affected components and features in use, and confirm which server and agent packages Fortra supports for that installation. After applying the package, verify that the relevant updated component is running; Fortra explicitly calls this out for boks_ksllogsd.
Is the BoKS autoregistration service affected?
Yes. FI-2026-017 (CVE-2026-12627) describes a critical memory-corruption flaw in boks_autoregisterd when it processes a client response. A remote attacker with network access to the service may trigger it. Fortra’s October 2 notes list an autoregistration proxy version overflow fix for the 8.1 and 9.0 server releases; confirm with Fortra that the package and component applicable to your installation address this advisory.
Do not confuse this October stack overflow with Fortra’s separate June 2026 disclosure, FI-2026-007 (CVE-2026-9862), which described OS command injection in the same service. The June advisory recommended restricting access to the service on default port 6507 until fixed builds were deployed and described disabling it as a workaround. That earlier mitigation relates to the June command-injection flaw; it is not, by itself, confirmation that the October issue is fixed.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

