BeyondTrust Remote Access Products Hit by 0-Day RCE Vulnerability
ID: 98e219cd-bb41-5fb0-aaf0-31a31d0e20fd
STIX ID: report--98e219cd-bb41-5fb0-aaf0-31a31d0e20fd
Feed Name: GBHackers
Threat Score
BeyondTrust disclosed CVE-2026-1731, a critical (CVSSv4 9.9) pre-authentication OS command injection that enables remote code execution against self-hosted BeyondTrust Remote Support (<=25.3.1) and Privileged Remote Access (<=24.3.4). Cloud/SaaS instances were patched on Feb 2, 2026, but on‑premise customers must urgently update to RS 25.3.2 and PRA 25.1.1 to avoid potential full system compromise; the issue was responsibly disclosed by Harsh Jaiswal and the Hacktron AI team.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
