[Threat Bulletin] TLP WHITE: Actively Exploited High-Severity Memory Overflow Zero-Day Flaw in Citrix NetScaler ADC, Gateway
[Threat Bulletins] TLP WHITE: Actively Exploited High-Severity Memory Overflow Zero-Day Flaw in Citrix NetScaler ADC and Gateway (CVE-2026-88779)
Analysis
On October 01, 2026, Fortra released software updates addressing eight vulnerabilities in its Core Privileged Access Manager (BoKS) tool, which centralizes account management and access enforcement across Unix and Linux operating systems. The patch set resolves three primary flaws:
- An authentication bypass involving predictable Active Directory password generation.
- A command injection flaw within the crlserver component.
- A stack buffer overflow that affects the autoregistration feature.
Below are the eight vulnerabilities patched by Fortra:
- CVE-2026-79901 (CVSS: 9.9 / Critical) - An authentication bypass flaw in BoKS Manager keytab-based Active Directory service account management caused by predictable pseudo-random password generation seeded using timestamps, permitting offline candidate verification.
- CVE-2026-12627 (CVSS: 9.8 / Critical) - A stack-based buffer overflow vulnerability in BoKS's autoregistration functionality (boks_autoregisterd) that allows remote attackers to trigger memory corruption.
- CVE-2026-79898 (CVSS: 9.1 / Critical) - An OS command injection flaw in crlserver that permits an authenticated user via BCC, WSI APIs, or CLI interfaces to substitute shell commands processed as root on the BoKS Master.
- CVE-2026-14316 (CVSS: 8.1 / High) - A heap-based buffer overflow vulnerability (CWE-122) exists in Fortra's boks_sshd revoked-key error handling.
- CVE-2026-79899 (CVSS: 7.9 / High) - An insecure temporary file vulnerability in the bccgethostcert utility due to missing a restrictive umask, allowing local users with access to BOKS_tmp to view sensitive cryptographic material.
- CVE-2026-79896 (CVSS: 7.5 / High) - An out-of-bounds read vulnerability in the custom TLS ClientHello component (boks_portmux).
- CVE-2026-79900 (CVSS: 6.5 / Medium) - A heap overflow vulnerability in Fortra boks_ksllogsd due to improper bounds checking of checksum algorithm names supplied in authenticated KSL start messages, allowing an authenticated client to write beyond the end of a heap allocation.
- CVE-2026-9864 (CVSS: 4.8 / Medium) - A predictable password generation vulnerability in the adjoin utility, where machine-account passwords generated during Active Directory join or password renewal operations have lower entropy than intended and are susceptible to prediction.
In the health sector, hospitals and medical facilities rely heavily on Linux and Unix environments to run core electronic health record platforms, laboratory information systems, and medical device gateways. Privileged access software manages administrative rights across these critical servers. An intruder gaining access via these vulnerabilities could compromise master directory credentials, manipulate medical data pipelines, or disrupt clinical workflows essential to patient care.
Securing these administrative access channels is vital for protecting sensitive patient data and maintaining compliance with healthcare privacy regulations. Health sector organizations frequently utilize automated systems and integrated directory services to streamline staff access, making flaws in directory synchronization and privilege management particularly significant risks for hospital networks. Implementing rapid vendor patches helps safeguard medical infrastructure against unauthorized operational disruptions.
View the detailed report below.
For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact: