logo

BeyondTrust fixes critical pre-auth bug allowing remote code execution

ID: 17249d34-3960-5774-92f1-025211cc588f

STIX ID: report--17249d34-3960-5774-92f1-025211cc588f

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-02-09

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

BeyondTrust released patches for a critical pre-auth remote code execution vulnerability (CVE-2026-1731, CVSS 9.9) affecting Remote Support (<=25.3.1) and older Privileged Remote Access (<=24.3.4). The flaw allows unauthenticated attackers to send crafted requests to execute OS commands remotely; fixes are RS 25.3.2+/Patch BT26-02-RS and PRA 25.1.1+/Patch BT26-02-PRA. SaaS customers were auto-patched on Feb 2, 2026; self-hosted administrators must manually apply the updates. Researchers estimate ~11,000 instances exposed online (about 8,500 on-prem), and technical details are being withheld to allow patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.