logo

Exploited in the Wild: Critical BeyondTrust Flaw (CVSS 9.9) Opens Door to Network Takeover

ID: 2afd14d0-aa75-52c7-bcf0-72cccc7d7720

STIX ID: report--2afd14d0-aa75-52c7-bcf0-72cccc7d7720

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-02-15

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical unauthenticated command-execution vulnerability (CVE-2026-1731, CVSS 9.9) in self-hosted BeyondTrust Remote Support and Privileged Remote Access is being actively exploited: attackers deploy SimpleHelp renamed as generic binaries to ProgramData, use SYSTEM to maintain persistence, perform AD discovery (e.g., AdsiSearcher, systeminfo, ipconfig), attempt to add accounts to high-privilege groups, and move laterally via PSexec and Impacket; cloud customers were auto-patched but self-hosted instances must apply vendor fixes immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.