ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

BeyondTrust Fixes Critical Pre-Auth RCE Vulnerability in Remote Support and PRA

criticalVulnerability exploited in the wildimportance 60CVE-2026-1731

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-1731
Pre-Authentication OS Command Injection RCE in BeyondTrust Remote Support and PRA

BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical (CVSS 4.0: 9.9) pre-authentication operating system command injection vulnerability (CWE-78). By sending specially crafted requests to the appliance, an unauthenticated remote attacker can execute operating system commands in the context of the site user, gaining code execution without credentials or user interaction. Any organization running RS or PRA appliances that are reachable from the internet, which is their typical deployment mode for remote support and privileged access, is affected. Exploitation is active: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-02-13 with known ransomware use, carries an EPSS of 89.5% (100th percentile), has a public proof-of-concept, and press coverage links the newly patched BeyondTrust RCE to fast-moving ransomware activity (Storm-1175). BeyondTrust has released fixes, so unpatched, internet-exposed instances should be treated as high-priority compromise targets.

Do: Upgrade all internet-exposed Remote Support and Privileged Remote Access appliances to the fixed releases in BeyondTrust's security advisory immediately, per the CISA KEV required action (apply vendor mitigations or discontinue use if mitigation is unavailable). Until patched, restrict network access to the appliance and review appliance/web logs for suspicious unauthenticated requests, given known ransomware exploitation and the availability of a public proof-of-concept.

9.990% KEV ransomware PoC
  • BeyondTrust Remote Support (RS)
  • BeyondTrust Privileged Remote Access (PRA) Certain older versions (per the CVE description); exact affected and fixed ranges per BeyondTrust's advisory
largeon the order of tens of thousands of internet-exposed RS/PRA appliance instances worldwide
Full article462 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananFeb 09, 2026Enterprise Security / Network Security

BeyondTrust has released updates to address a critical security flaw impacting Remote Support (RS) and Privileged Remote Access (PRA) products that, if successfully exploited, could result in remote code execution.

"BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability," the company said in an advisory released February 6, 2026.

"By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user."

The vulnerability, categorized as an operating system command injection, has been assigned the CVE identifier CVE-2026-1731. It's rated 9.9 on the CVSS scoring system.

BeyondTrust said successful exploitation of the shortcoming could allow an unauthenticated remote attacker to execute operating system commands in the context of the site user, resulting in unauthorized access, data exfiltration, and service disruption.

The issue affects the following versions -

  • Remote Support versions 25.3.1 and prior
  • Privileged Remote Access versions 24.3.4 and prior

It has been patched in the following versions -

  • Remote Support - Patch BT26-02-RS, 25.3.2 and later
  • Privileged Remote Access - Patch BT26-02-PRA, 25.1.1 and later

The company is also urging self-hosted customers of Remote Support and Privileged Remote Access to manually apply the patch if their instance is not subscribed to automatic updates. Those running a Remote Support version older than 21.3 or on Privileged Remote Access older than 22.1 are also required to upgrade to a newer version to apply this patch.

"Self-hosted customers of PRA may also upgrade to 25.1.1 or a newer version to remediate this vulnerability," it added.

According to security researcher and Hacktron AI co-founder Harsh Jaiswal, the vulnerability was discovered on January 31, 2026, through an artificial intelligence (AI)-enabled variant analysis, adding that it found about 11,000 instances exposed to the internet. Additional details of the flaw have been withheld to give users time to apply the patches.

"About ~8,500 of those are on-prem deployments, which remain potentially vulnerable if patches aren't applied," Jaiswal and Mohan Sri Rama Krishna Pedhapati said.

With security flaws in BeyondTrust Privileged Remote Access and Remote Support having come under active exploitation in the past, it's essential that users update to the latest version as soon as possible for optimal protection.

Update

According to data from attack surface management platform Censys, there are about 190,832 exposed web properties, although it's currently not clear how many of those are susceptible to the flaw. The majority of the exposures are in the U.S., followed by Germany, Canada, the U.K., France, Switzerland, Australia, and India.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/02/beyondtrust-fixes-critical-pre-auth-rce.html