logo

BeyondTrust Fixes Critical Pre-Auth RCE Vulnerability in Remote Support and PRA

ID: 98cb2ad7-3e89-53ab-a87d-a3e4cea9babf

STIX ID: report--98cb2ad7-3e89-53ab-a87d-a3e4cea9babf

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-02-09

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

**BeyondTrust CVE-2026-1731 (critical pre-auth RCE)**: BeyondTrust disclosed a critical command-injection vulnerability (CVSS 9.9) impacting Remote Support (≤25.3.1) and Privileged Remote Access (≤24.3.4) that could allow unauthenticated remote command execution. Patches are available (RS 25.3.2+, PRA 25.1.1+) and the vendor urges self-hosted customers to apply them; researcher Harsh Jaiswal reported the flaw was discovered via AI-enabled analysis on Jan 31, 2026 and found ~11,000 internet-exposed instances (≈8,500 on-prem).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.