logo

CISA: Second BeyondTrust Vulnerability Added to KEV Catalog

ID: ec347e97-9cf1-5215-9669-e51225577296

STIX ID: report--ec347e97-9cf1-5215-9669-e51225577296

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2025-01-15

Date Updated: 2026-04-21

Author: Kristina Beek, Associate Editor, Dark Reading

...
...

CISA warned federal agencies to patch CVE-2024-12686 (BT24-11), a command injection flaw in BeyondTrust Remote Support products that was added to the Known Exploited Vulnerabilities catalog after investigation of a US Treasury data breach; BeyondTrust reports cloud instances patched and self-hosted patches released, while the breach has been attributed to the China-linked APT "Silk Typhoon."

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.