{"api_version":"v1","generated_at":"2026-10-09T13:45:00+00:00","product":{"cve_count":6,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-fortra-core-privileged-access-manager-boks-622f49fe24af","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"Core Privileged Access Manager (BoKS)","next_cursor":null,"observations":[{"affected":"Core Privileged Access Manager (BoKS): 8.1.0.0 < 8.1.0.30, 10.1.0.0 < 10.1.1.0","affected_versions_present":true,"cve_id":"CVE-2026-14316","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-14316","fixed":"Upgrade to a patched version.","last_modified":"2026-10-01T16:32:54.604Z","patch_url":"https://www.fortra.com/security/advisories/product-security/fi-2026-019","primary_source":"","published":"2026-10-01T16:16:36.508Z"},{"affected":"Core Privileged Access Manager (BoKS): 8.1.0.0 \u2264 8.1.0.29, 9.0.0.0 \u2264 9.0.0.5","affected_versions_present":true,"cve_id":"CVE-2026-9864","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-9864","fixed":"Upgrade to a fixed boks-client release newer than 8.1.0.29 or 9.0.0.5, then rotate machine-account passwords generated by affected versions.","last_modified":"2026-10-01T16:16:15.483Z","patch_url":"https://www.fortra.com/security/advisories/product-security/fi-2026-018","primary_source":"","published":"2026-10-01T16:00:25.899Z"},{"affected":"boks-server 8.1.0.0 \u2264 boks-server 8.1.0.22; boks-server 9.0.0.0 \u2264 boks-server 9.0.0.4","affected_versions_present":true,"cve_id":"CVE-2026-9863","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-9863","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-15T16:08:58.885Z","patch_url":"","primary_source":"","published":"2026-06-15T15:17:19.607Z"},{"affected":"boks-server 8.1.0.0 \u2264 boks-server 8.1.0.22; boks-server 9.0.0.0 \u2264 boks-server 9.0.0.4","affected_versions_present":true,"cve_id":"CVE-2026-9862","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-9862","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-15T16:09:28.297Z","patch_url":"","primary_source":"","published":"2026-06-15T15:10:08.708Z"},{"affected":"This issue affects BoKS Server Agent 9.0 instances that support yescrypt and are running in a BoKS 8.1 domain. The affected platforms are: Debian 11, 12, 13, RedHat 9, 10 and Ubuntu 24.","affected_versions_present":true,"cve_id":"CVE-2025-13532","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-13532","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-12-16T20:23:51.768Z","patch_url":"","primary_source":"","published":"2025-12-16T20:01:02.743Z"},{"affected":"\u2264 7.2.0.17; \u2264 8.1.0.22; \u2264 8.1.1.7; \u2264 9.0.0.1","affected_versions_present":true,"cve_id":"CVE-2025-5141","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-5141","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-08-29T20:11:13.423Z","patch_url":"","primary_source":"","published":"2025-06-17T19:30:51.781Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"Fortra"}}
