CVE-2026-1731: RCE Risk in BeyondTrust RS and PRA
ID: e4b4dc90-12e5-589b-bf0c-349052b844ea
STIX ID: report--e4b4dc90-12e5-589b-bf0c-349052b844ea
Feed Name: SOCRadar Blog
Threat Score
BeyondTrust disclosed CVE-2026-1731, an unauthenticated OS command-injection (CVSSv4 9.9) in Remote Support and Privileged Remote Access that enables pre-auth remote code execution; affected RS and PRA versions and corresponding patches/upgrade paths are specified, and emerging evidence of active exploitation, widespread scanning, and a CISA KEV listing (with ~11,000 internet-exposed instances) make immediate remediation of internet-facing on-prem deployments imperative.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
