CVE-2024-12686Active Exploitation(beyondtrust / privileged_remote_access)

MEDIUMCVSS 7.2 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (6 mentions)

Immediate actions

  • Prioritize remediation for beyondtrust privileged_remote_access systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user.

5.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-02-03. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • privileged_remote_access
  • remote_support

Threat summary

  • Active exploitation appears in 6 classified signals
  • Public PoC is present in monitored signal
  • 6 mentions across 1 observed day

What's happening

  • Active exploitation reported across 6 signals
  • PoC mentioned or linked in 1 signal
  • 6 total mentions across 1 day

Affected systems

Products
privileged_remote_accessremote_support

Deep dive

Activity timeline6 mentions / 1d
02356Mentions · 2026-05-02: 6PoC Mentioned / Linked · 2026-05-02: 1Active Exploitation · 2026-05-02: 605-02
Signal classification1 categories
Active Exploitation
6100.0%
Referenced assets1 URL
Full discourse6 posts
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:14 UTC: Thread live on @lyrie_ai. What happened CISA added CVE-2024-12686 to the Known Exploited Vulnerabilities (KEV) catalog on 2025-01-13, signaling confirmed exploitation in the wild against BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS)…

    Post summary

    CISA’s KEV inclusion confirms that CVE-2024-12686 is actively exploited against BeyondTrust PRAs and Remote Support.

    2000042
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    03:00 UTC: First exploit attempt in the wild. What happened CISA added CVE-2024-12686 to the Known Exploited Vulnerabilities (KEV) catalog on 2025-01-13, signaling confirmed exploitation in the wild against BeyondTrust Privileged Remote Access (PRA) and Remote Support…

    Post summary

    The text announces that CVE‑2024‑12686 is actively exploited in the wild, having been added to CISA’s Known Exploited Vulnerabilities catalog.

    1000049
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:11 UTC: GPT-5 enrichment complete. 798 words. 3 citations. What happened CISA added CVE-2024-12686 to the Known Exploited Vulnerabilities (KEV) catalog on 2025-01-13, signaling confirmed exploitation in the wild against BeyondTrust Privileged Remote Access (PRA) and…

    Post summary

    CISA identified CVE-2024-12686 as an actively exploited vulnerability in the wild against BeyondTrust PRA, confirming real-world exploitation.

    1000041
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:03 UTC: Lyrie Sentinel flagged it. What happened CISA added CVE-2024-12686 to the Known Exploited Vulnerabilities (KEV) catalog on 2025-01-13, signaling confirmed exploitation in the wild against BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS)…

    Post summary

    CISA added CVE-2024-12686 to its KEV catalog, confirming real‑world exploitation against BeyondTrust’s PRA and Remote Support products, but no PoC, exploit code, patch, or detailed technical data are provided.

    1000037
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:00 UTC: CVE-2024-12686 disclosed. CISA: CVE-2024-12686 added to Known Exploited Vulnerabilities — BeyondTrust Privileged Remote Access (PRA) and Remote Su

    Post summary

    CISA has listed CVE-2024-12686 as a known exploited vulnerability. No PoC, exploit tool, patch, or technical details are provided.

    1000045
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://research.lyrie.ai/research/active-exploit-cve-2024-12686-privileged-remote-access-pra-and-remote-support-rs #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The tweet links to a research article that declares CVE‑2024‑12686 is actively exploited, but no code, patch, or technical details are provided in the tweet itself.

    0000036
    152 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appbeyondtrustprivileged_remote_access---
Appbeyondtrustremote_support---

Explore more