logo

BeyondTrust Flaw Used for Web Shells, Backdoors, and Data Exfiltration

ID: 9d43b1a1-63ea-59d4-a5b3-04ab2a718188

STIX ID: report--9d43b1a1-63ea-59d4-a5b3-04ab2a718188

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-02-20

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Palo Alto Networks Unit 42 and reporting indicate active in-the-wild exploitation of CVE-2026-1731 (CVSS 9.9) in BeyondTrust RS/PRA appliances, enabling remote OS command execution via a WebSocket-accessible script; attackers have leveraged the flaw to obtain administrative access, deploy web shells and malware (including VShell and Spark RAT), perform lateral movement and exfiltrate sensitive data, and the issue has been added to CISA's KEV catalog and observed in ransomware activity—primary impact is on internet-facing, self-hosted appliances where patches were not applied.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.