logo

BeyondTrust Remote Access Products 0-Day Vulnerability Allows Remote Code Execution

ID: 394e802d-abab-505c-af28-b1f74af6b6d3

STIX ID: report--394e802d-abab-505c-af28-b1f74af6b6d3

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-02-07

Date Updated: 2026-04-21

Author: Guru Baran

...
...

BeyondTrust disclosed a critical pre-authentication OS command-injection vulnerability (CVE-2026-1731) in Remote Support (<=25.3.1) and Privileged Remote Access (<=24.3.4) that permits unauthenticated remote command execution; SaaS customers were automatically patched on 2026-02-02 while self-hosted deployments must apply patches BT26-02-RS or BT26-02-PRA (older versions must upgrade first).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.