Fortra® Security & Trust Center

Blog

Fortra Patch Priority Index for May 2026

Fortra’s May 2026 Patch Priority Index ranks the month’s most important vulnerabilities by real-world enterprise risk rather than severity score alone. It emphasizes prioritizing internet-facing and network-accessible systems first — especially Palo Alto GlobalProtect, Windows DNS, and Microsoft Exchange — while tracking cloud-side remediated issues separately when no customer patching is required.
Security Advisory

Privilege Escalation in Fortra File Integrity Monitoring (FIM)

Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0 may assign incorrect or elevated effective permissions to users created by the tetool import command while FIM is running, particularly when the import also creates or changes roles or role-permission relationships.
Security Advisory

Stored XSS in Fortra File Integrity Monitoring (FIM)

Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0.1 contain a stored cross-site scripting (XSS) vulnerability in the Asset View UI component. An authenticated user with sufficient privileges to create or modify affected node or database configuration fields could store script content that may be rendered as HTML instead of safely escaped text when the...
Blog

Phishing Campaign Targets Banks with Fileless Phantom Stealer Malware

Executive SummaryFortra Intelligence and Research Experts (FIRE) have identified an active phishing campaign targeting high-capital organizations, particularly those operating within the banking sector. The campaign uses evasive techniques to distribute Phantom Stealer, a commercially available Malware-as-a-Service (MaaS) infostealer used to steal credentials, financial data, and sensitive...
Security Advisory

Core Privileged Access Manager (BoKS) upgrade tooling command injection vulnerability

Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching may be able to cause commands to be executed on the BoKS Master during client version handling.
Emerging Threats

Oracle PeopleSoft PeopleTools Zero-day Vulnerability

Oracle has identified a critical zero-day vulnerability in PeopleSoft PeopleTools, tracked as CVE-2026-35273, with a CVSS base score of 9.8. This vulnerability allows unauthenticated remote code execution and is actively exploited by the ShinyHunters group in data theft attacks. CVERiskScoreCVE-2026-35273CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H9.8, CriticalExploitation of this vulnerability...