Fortra Fixes Critical Bugs in BoKS PAM Platform
Fortra has patched critical vulnerabilities in BoKS ServerControl, its Unix/Linux privileged access management platform. The flaws include authentication bypass, shell command execution, and memory corruption.

Fortra has released patches for BoKS, its Unix and Linux privileged access management (PAM) platform, fixing critical flaws that include authentication bypass, shell command execution, and memory corruption, SecurityWeek reported October 3.
BoKS (BoKS ServerControl) is enterprise PAM software used to centrally manage and enforce access controls on Unix and Linux servers, covering session recording, privilege escalation controls, and access policy enforcement. It sits at the control plane of Unix infrastructure in regulated industries and critical infrastructure operators.
What the patches fix
Fortra has not published individual CVE identifiers at time of publication. Based on SecurityWeek’s reporting, the patched bugs fall into three classes.
Authentication bypass. An attacker could circumvent access controls without presenting valid credentials. In a PAM product, this is the kind of flaw that undoes the entire point of the software.
Shell command execution. A separate flaw could allow arbitrary command execution on the host. Combined with an auth bypass, this is effectively an unauthenticated path to running commands on systems protected by BoKS.
Memory corruption. A third class of flaw that can cause crashes or, depending on exploit conditions, code execution.
Full technical details and affected version ranges should be available via Fortra’s security advisory. Check Fortra’s security portal for the current advisory and patch guidance.
What to do
Patch BoKS. Authentication bypass in PAM software negates the access controls your Unix infrastructure depends on. If your BoKS deployment is reachable from internal segments, an auth bypass combined with shell command execution gives an attacker a direct path to every system BoKS manages. That is a significant blast radius.
If patching is not immediate, restrict network access to BoKS management interfaces to trusted segments and enable alerting for unexpected authentication activity in the interim.
For context on the broader PAM security pattern, see our coverage of BeyondTrust Remote Support auth bypass flaws from July 2026.
Found this useful? Share it.