logo

Attackers Exploit Critical BeyondTrust Flaw to Seize Full Active Directory Control

ID: 68f97f42-806b-5885-a970-a74f05a49cf2

STIX ID: report--68f97f42-806b-5885-a970-a74f05a49cf2

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-02-16

Date Updated: 2026-04-22

Author: Divya

...
...

**Executive summary:** A critical unauthenticated command-injection vulnerability (CVE-2026-1731) in self-hosted BeyondTrust Remote Support and Privileged Remote Access is being actively exploited; attackers deploy renamed SimpleHelp binaries, escalate privileges to Domain/Enterprise Admins, enumerate Active Directory with tools like AdsiSearcher, and move laterally using PSExec and Impacket—CISA has added the flaw to its KEV catalog and on-premises instances must apply patches BT26-02-RS or BT26-02-PRA immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.