logo

Researchers Observe In-the-Wild Exploitation of BeyondTrust CVSS 9.9 Vulnerability

ID: f7e0dcc7-21e9-5dc1-b8cd-803b6201b932

STIX ID: report--f7e0dcc7-21e9-5dc1-b8cd-803b6201b932

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-02-13

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Multiple high-severity vulnerabilities are being actively exploited: BeyondTrust products are facing in‑the‑wild pre‑auth RCE exploitation (CVE‑2026‑1731) and CISA added four other exploited CVEs to its KEV list, including an Apple zero‑day and a SolarWinds/Notepad++ related set. The report highlights a Notepad++ update supply‑chain compromise attributed to China‑linked Lotus Blossom that delivered the Chrysalis backdoor to selected targets, notes available patches and FCEB remediation deadlines, and underscores rapid weaponization of disclosed flaws.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.