logo

Critical BeyondTrust RCE flaw now exploited in attacks, patch now

ID: 11f988b2-9594-50cc-876a-aa3d20a25617

STIX ID: report--11f988b2-9594-50cc-876a-aa3d20a25617

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-02-12

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Critical pre-auth remote code execution vulnerability CVE-2026-1731 (CVSS 9.9) impacting BeyondTrust Remote Support (≤25.3.1) and Privileged Remote Access (≤24.3.4) is being actively exploited after a PoC was published; attackers abuse the /get_portal_info endpoint to obtain the X-Ns-Company value and establish WebSocket channels to execute commands. BeyondTrust auto-patched cloud SaaS instances on Feb 2, 2026, but on-premises deployments (~8,500 of ~11,000 exposed) require manual patching—unpatched systems should be assumed compromised and patched immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.