logo

CVE-2026-1731: RCE Risk in BeyondTrust RS and PRA

ID: e4b4dc90-12e5-589b-bf0c-349052b844ea

STIX ID: report--e4b4dc90-12e5-589b-bf0c-349052b844ea

Feed Name: SOCRadar Blog

Threat Score
90/100

Date Published: 2026-02-10

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

BeyondTrust disclosed CVE-2026-1731, an unauthenticated OS command-injection (CVSSv4 9.9) in Remote Support and Privileged Remote Access that enables pre-auth remote code execution; affected RS and PRA versions and corresponding patches/upgrade paths are specified, and emerging evidence of active exploitation, widespread scanning, and a CISA KEV listing (with ~11,000 internet-exposed instances) make immediate remediation of internet-facing on-prem deployments imperative.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.