logo

Surge in Bomgar RMM Exploitation Demonstrates Supply Chain Risk

ID: ab68dfc1-fc14-5e01-b0ca-0f18b8257ee0

STIX ID: report--ab68dfc1-fc14-5e01-b0ca-0f18b8257ee0

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2026-04-21

Date Updated: 2026-04-21

Author: Elizabeth Montalbano

...
...

Researchers at Huntress observed a recent surge exploiting a critical unauthenticated RCE (CVE-2026-1731) in Bomgar/BeyondTrust Remote Support appliances, allowing attackers to gain upstream access to RMM servers, deploy remote management tools (AnyDesk, Atera), create admin accounts, and in several cases deploy LockBit ransomware; incidents have impacted MSPs and multiple downstream customers, demonstrating significant supply-chain risk and prompting recommendations to patch vulnerable systems and monitor for malicious RMM activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.