Exploited in the Wild: Critical BeyondTrust Flaw (CVSS 9.9) Opens Door to Network Takeover
ID: 2afd14d0-aa75-52c7-bcf0-72cccc7d7720
STIX ID: report--2afd14d0-aa75-52c7-bcf0-72cccc7d7720
Feed Name: securityonline.info
A critical unauthenticated command-execution vulnerability (CVE-2026-1731, CVSS 9.9) in self-hosted BeyondTrust Remote Support and Privileged Remote Access is being actively exploited: attackers deploy SimpleHelp renamed as generic binaries to ProgramData, use SYSTEM to maintain persistence, perform AD discovery (e.g., AdsiSearcher, systeminfo, ipconfig), attempt to add accounts to high-privilege groups, and move laterally via PSexec and Impacket; cloud customers were auto-patched but self-hosted instances must apply vendor fixes immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
