logo

CVE-2026-1731: Critical BeyondTrust Flaw (CVSS 9.9) Allows Pre-Auth RCE

ID: 7542c901-d730-504f-a320-45c7ad2c5b4d

STIX ID: report--7542c901-d730-504f-a320-45c7ad2c5b4d

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-02-09

Date Updated: 2026-04-23

Author: Ddos

...
...

BeyondTrust disclosed a critical pre-authentication remote code execution vulnerability (CVE-2026-1731, CVSSv4 9.9) affecting Remote Support and older Privileged Remote Access versions that allows unauthenticated attackers to execute OS commands as the site user; SaaS instances were auto-patched on Feb 2, 2026, while self-hosted appliances must be manually upgraded (RS → 25.3.2+, PRA → 25.1.1+, with older versions requiring staged upgrades).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.