Pre-Authentication OS Command Injection RCE in BeyondTrust Remote Support and PRA
CISA: BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability
CVSS 4.0
9.9critical
EPSS
90%p100
Published
()
KEV added
AI analysis
BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical (CVSS 4.0: 9.9) pre-authentication operating system command injection vulnerability (CWE-78). By sending specially crafted requests to the appliance, an unauthenticated remote attacker can execute operating system commands in the context of the site user, gaining code execution without credentials or user interaction. Any organization running RS or PRA appliances that are reachable from the internet, which is their typical deployment mode for remote support and privileged access, is affected. Exploitation is active: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-02-13 with known ransomware use, carries an EPSS of 89.5% (100th percentile), has a public proof-of-concept, and press coverage links the newly patched BeyondTrust RCE to fast-moving ransomware activity (Storm-1175). BeyondTrust has released fixes, so unpatched, internet-exposed instances should be treated as high-priority compromise targets.
What to do: Upgrade all internet-exposed Remote Support and Privileged Remote Access appliances to the fixed releases in BeyondTrust's security advisory immediately, per the CISA KEV required action (apply vendor mitigations or discontinue use if mitigation is unavailable). Until patched, restrict network access to the appliance and review appliance/web logs for suspicious unauthenticated requests, given known ransomware exploitation and the availability of a public proof-of-concept.
Affected
BeyondTrust Remote Support (RS)
—
BeyondTrust Privileged Remote Access (PRA)
Certain older versions (per the CVE description); exact affected and fixed ranges per BeyondTrust's advisory
Estimated exposure
largeon the order of tens of thousands of internet-exposed RS/PRA appliance instances worldwide — BeyondTrust RS/PRA are internet-facing enterprise remote-access gateways typically deployed per customer site at tens of thousands of vendor-reported enterprise customers, and public internet scans historically show BeyondTrust appliances…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.
CISA Known Exploited Vulnerability
Affected
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
FBI and Lumen disrupted QTFY's QScan and QTRouter botnet platforms used by Chinese state-sponsored hackers to conceal intrusions into U.S. agencies.
The U.S. DoJ announced court-authorized seizure of domains behind QScan and QTRouter, operated by the Chinese state-sponsored group QTFY and employed by Nanjing Xinjiuwei Network Technology Company. QTFY has been active since May 2018 and targeted NASA, the Federal Reserve, the Department of Energy, DoJ, HHS, NIH, the U.S. Senate, and academic institutions. QScan exploits vulnerable IoT devices, feeding them into QTRouter, an OpenWrt-based proxy obfuscation network likened to an operational relay box (ORB) that masks attack origins. The group exploited zero-days such as Ivanti CSA flaws CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380, plus numerous N-days, and maintained persistence with RATs, web shells, and legitimate credentials.
Microsoft reports China-linked ransomware group Storm-1175 switched from Medusa to a new C++ strain, StormEncryptor, likely exploiting N-able flaw CVE-2026-18577.
Microsoft Threat Intelligence reports that the financially motivated, China-linked group Storm-1175 began deploying a new ransomware strain called StormEncryptor on August 2, 2026, replacing its previous Medusa ransomware. StormEncryptor is written in C++, appends the .encrypted extension to files, and drops a !!!README_FIRST!!!.txt ransom note in each scanned directory. Microsoft assesses the group is likely exploiting CVE-2026-18577, an authentication bypass in N-able disclosed on August 2, 2026 and added to CISA's Known Exploited Vulnerabilities catalog the next day. Since 2023, Storm-1175 has exploited more than 16 vulnerabilities in products including Microsoft Exchange, Ivanti, ConnectWise ScreenConnect, JetBrains TeamCity, SimpleHelp, CrushFTP, and GoAnywhere MFT, often moving from initial access to data theft and ransomware deployment within days.