ZeroHour
Security Affairspublished ()ingested @securityaffairs

Security Affairs newsletter Round 563 by Pierluigi Paganini

criticalRansomware exploited in the wildimportance 60CVE-2026-1731

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-1731
Pre-Authentication OS Command Injection RCE in BeyondTrust Remote Support and PRA

BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical (CVSS 4.0: 9.9) pre-authentication operating system command injection vulnerability (CWE-78). By sending specially crafted requests to the appliance, an unauthenticated remote attacker can execute operating system commands in the context of the site user, gaining code execution without credentials or user interaction. Any organization running RS or PRA appliances that are reachable from the internet, which is their typical deployment mode for remote support and privileged access, is affected. Exploitation is active: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-02-13 with known ransomware use, carries an EPSS of 89.5% (100th percentile), has a public proof-of-concept, and press coverage links the newly patched BeyondTrust RCE to fast-moving ransomware activity (Storm-1175). BeyondTrust has released fixes, so unpatched, internet-exposed instances should be treated as high-priority compromise targets.

Do: Upgrade all internet-exposed Remote Support and Privileged Remote Access appliances to the fixed releases in BeyondTrust's security advisory immediately, per the CISA KEV required action (apply vendor mitigations or discontinue use if mitigation is unavailable). Until patched, restrict network access to the appliance and review appliance/web logs for suspicious unauthenticated requests, given known ransomware exploitation and the availability of a public proof-of-concept.

9.990% KEV ransomware PoC
  • BeyondTrust Remote Support (RS)
  • BeyondTrust Privileged Remote Access (PRA) Certain older versions (per the CVE description); exact affected and fixed ranges per BeyondTrust's advisory
largeon the order of tens of thousands of internet-exposed RS/PRA appliance instances worldwide
Full article388 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini February 15, 2026

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

International Press – Newsletter

Cybercrime

Romanian oil pipeline operator Conpet discloses cyberattack    

Flickr Security Incident Tied to Third-Party Email System  

Senegal’s File Automation Directorate Hit by Cyberattack, Hackers Claim 139TB Data Breach  

Odido warns of data breach: millions of customer data stolen in cyber attack

BADIIS to the Bone: New Insights to a Global SEO Poisoning Campaign 

Malware

Threat Alert: TeamPCP, An Emerging Force in the Cloud Native and Ransomware Landscape  

Reynolds: Defense Evasion Capability Embedded in Ransomware Payload  

AgreeToSteal: The First Malicious Outlook Add-In Leads to 4,000 Stolen Credentials  

Fake recruiter campaign targets crypto devs

Hacking

Active Exploitation of SolarWinds Web Help Desk  

CVE-2026-1731: Pre-Auth RCE in BeyondTrust Remote Support & PRA  

Hacker Conversations: Professional Hacker Douglas Day  

Apple Fixes Exploited Zero-Day Affecting iOS, macOS, and Apple Devices

Reconnaissance Has Begun for the New BeyondTrust RCE (CVE-2026-1731): Here’s What We See So Far  

2026-01-14: The Day the telnet Died  

Intelligence and Information Warfare

Largest Multi-Agency Cyber Operation Mounted to Counter Threat Posed by Advanced Persistent Threat (APT) Actor UNC3886 to Singapore’s Telecommunications Sector  

Dutch Authorities Confirm Ivanti Zero-Day Exploit Exposed Employee Contact Data

Stan Ghouls targeting Russia and Uzbekistan with NetSupport RAT 

Russia’s hybrid attacks throughout Europe are becoming more dangerous  

UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering

North Korean IT workers are secretly employed in Norwegian companies 

GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use       

New threat actor, UAT-9921, leverages VoidLink framework in campaigns

Beyond the Battlefield: Threats to the Defense Industrial Base     

Fake recruiter campaign targets crypto devs  

Cybersecurity

Commission responds to cyber-attack on its central mobile infrastructure 

The February 2026 Security Update Review  

Conduent Breach Hits Volvo Group: Nearly 17,000 Employees’ Data Exposed  

Hacker linked to Epstein removed from Black Hat cyber conference website

Fintech lending giant Figure confirms data breach 

Weaponising AI: The New Cyber Attack Surface  

Russia tries to block WhatsApp, Telegram in communication blockade

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



you might also like

leave a comment

Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/187996/security/security-affairs-newsletter-round-563-by-pierluigi-paganini-international-edition.html