• News/
  • https://www.bleepingcomputer.com/news/security/critical-beyondtrust-rce-flaw-now-exploited-in-attacks-patch-now/

Critical BeyondTrust RCE flaw now exploited in attacks, patch now

BleepingComputer
·
Lawrence Abrams
·
Published Feb 12, 2026
·
Updated

A critical pre-authentication remote code execution vulnerability in BeyondTrust Remote Support and Privileged Remote Access appliances is now being exploited in attacks after a PoC was published online. Tracked as CVE-2026-1731 and assigned a near-maximum CVSS score of 9.9, the flaw affects BeyondTrust Remote Support versions 25.3.1 and earlier and Privileged Remote Access versions 24.3.4 and earlier. BeyondTrust disclosed the vulnerability on February 6, warning that unauthenticated attackers could exploit it by sending specially crafted client requests. "BeyondTrust Remote Support and older versions of Privileged Remote Access contain a critical pre-authentication remote code execution vulnerability that may be triggered through specially crafted client requests," explained BeyondTrust. "Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of the site user. Successful exploitation requires no authentication or user interaction and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption." BeyondTrust automatically patched all Remote Support and Privileged Remote Access SaaS instances on February 2, 2026, but on-premise customers must install patches manually. Hacktron discovered the vulnerability and responsibly disclosed it to BeyondTrust on January 31. Hacktron says approximately 11,000 BeyondTrust Remote Support instances were exposed online, with around...

Read full article

Affected Software

2 affected components
BeyondTrust Remote Support<=25.3.1
BeyondTrust Privileged Remote Access<=24.3.4

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical remote code execution vulnerability in BeyondTrust's Remote Support and Privileged Remote Access products that is currently being exploited in attacks.

2

What security implications are discussed in this article?

The article highlights that the pre-authentication RCE vulnerability could allow attackers to execute arbitrary code on affected systems without authentication.

3

What products are affected by the vulnerability mentioned in the article?

The affected products include BeyondTrust Remote Support (up to version 25.3.1) and BeyondTrust Privileged Remote Access (up to version 24.3.4).

4

What should users do to protect themselves from this vulnerability?

Users are advised to apply the available patches immediately to mitigate the risk of exploitation.

5

What is the CVE identifier for the vulnerability discussed in the article?

The vulnerability is tracked as CVE-2026-1731.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203