logo

BeyondTrust warns of critical RCE flaw in remote support software

ID: d9425186-3dfc-5acb-b001-3104b77bce1a

STIX ID: report--d9425186-3dfc-5acb-b001-3104b77bce1a

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-02-09

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

BeyondTrust disclosed a critical pre-auth remote code execution vulnerability (CVE-2026-1731) in Remote Support and Privileged Remote Access that allows unauthenticated OS command execution via crafted client requests; BeyondTrust has secured cloud instances and released patches (Remote Support 25.3.2+, Privileged Remote Access 25.1.1+), while researchers warn roughly 11,000 internet-exposed instances (about 8,500 on-prem) could be vulnerable — no known active exploitation has been reported, though prior BeyondTrust zero-days were exploited by actors linked to the Silk Typhoon group.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.