BeyondTrust Fixes Critical Pre-Auth RCE Vulnerability in Remote Support and PRA
ID: 98cb2ad7-3e89-53ab-a87d-a3e4cea9babf
STIX ID: report--98cb2ad7-3e89-53ab-a87d-a3e4cea9babf
Feed Name: The Hacker News
**BeyondTrust CVE-2026-1731 (critical pre-auth RCE)**: BeyondTrust disclosed a critical command-injection vulnerability (CVSS 9.9) impacting Remote Support (≤25.3.1) and Privileged Remote Access (≤24.3.4) that could allow unauthenticated remote command execution. Patches are available (RS 25.3.2+, PRA 25.1.1+) and the vendor urges self-hosted customers to apply them; researcher Harsh Jaiswal reported the flaw was discovered via AI-enabled analysis on Jan 31, 2026 and found ~11,000 internet-exposed instances (≈8,500 on-prem).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
