SecAlerts
B

BeyondTrust

Security Risk Profile

71
/100
high

Security Risk Score

Comprehensive risk assessment based on 48 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from October 26, 2017 to present

48
Total CVEs
32
Critical+High
8
Exploited
30
Unpatched

Threat Assessment

Avg CVSS
7.8
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
30
Critical/High
Risk Level
71/100
high
⚠️ 8 Active Exploits 4 Zero-Days🆕 2Fresh (<7d)📈 2 in Last 30 Days

Severity Distribution

Critical
8
High
24
Medium
6
Low
2

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
9

Age Distribution

Common Weaknesses (CWE)

1
Command Injection
4
2
Infoleak
3
3
OS Command Injection
2
4
SQL Injection
2
5
XSS
2

Most Affected Products

1. BeyondTrust Remote Support29
2. BeyondTrust Privileged Remote Access24
3. BeyondTrust Privilege Management for Windows17
4. IBM Security Guardium6
5. BeyondTrust Beyondinsight Password Safe4

Recent Vulnerabilities

See more →
CVE-2026-40145
CVSS 7.1high

Control protections bypass in BeyondTrust Endpoint Privilege Management (Windows deployment) support utility

Aug 17, 2026🔧 No Patch
CVE-2026-40144
CVSS 7.3high

Memory corruption vulnerability in Endpoint Privilege Management (Windows deployments)

Aug 17, 2026🔧 No Patch
bleepingcomputer-20260707081210
unknown

BeyondTrust warns of critical flaws in remote access software

Jul 7, 2026🔧 No Patch
CVE-2026-40141
CVSS 8.5high

High-Severity Vulnerability In Web Application Component of BeyondTrust Remote Support and Privileged Remote Access

Jul 6, 2026🔧 No Patch
CVE-2026-40140
CVSS 8.7high

High-Severity Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access

Jul 6, 2026🔧 No Patch
CVE-2026-40139
CVSS 9.2critical

Critical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access

Jul 6, 2026🔧 No Patch
CVE-2026-40138
CVSS 9.2critical

Critical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access

Jul 6, 2026🔧 No Patch
https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-beyondtrust-flaw-within-three-days/
unknown

CISA gives feds 3 days to patch actively exploited BeyondTrust flaw

Feb 16, 2026⚠ Exploited🔧 No Patch
https://reddit.com/r/sysadmin/comments/1r3wb9v/beyondtrust_gets_hit_again_preauth_rce_in_remote/
unknown

BeyondTrust Gets Hit Again: Pre-Auth RCE in Remote Support Tools

Feb 13, 2026🔧 No Patch
https://www.bleepingcomputer.com/news/security/critical-beyondtrust-rce-flaw-now-exploited-in-attacks-patch-now/
unknown

Critical BeyondTrust RCE flaw now exploited in attacks, patch now

Feb 12, 2026⚠ Exploited⚡ Zero-Day🔧 No Patch

Monitor BeyondTrust in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.