logo

BeyondTrust Remote Access Products Hit by 0-Day RCE Vulnerability

ID: 98e219cd-bb41-5fb0-aaf0-31a31d0e20fd

STIX ID: report--98e219cd-bb41-5fb0-aaf0-31a31d0e20fd

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-02-09

Date Updated: 2026-06-18

Author: Divya

...
...

BeyondTrust disclosed CVE-2026-1731, a critical (CVSSv4 9.9) pre-authentication OS command injection that enables remote code execution against self-hosted BeyondTrust Remote Support (<=25.3.1) and Privileged Remote Access (<=24.3.4). Cloud/SaaS instances were patched on Feb 2, 2026, but on‑premise customers must urgently update to RS 25.3.2 and PRA 25.1.1 to avoid potential full system compromise; the issue was responsibly disclosed by Harsh Jaiswal and the Hacktron AI team.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.