
#threatreport #LowCompleteness Reconnaissance Has Begun for the New BeyondTrust RCE (CVE-2026-1731): Here's What We See So Far | 12-02-2025 Source: https://www.greynoise.io/blog/reconnaissance-beyondtrust-rce-cve-2026-1731 Key details below ↓ 🧑💻Actors/Campaigns: Hafnium 💀Threats: Beyondtrust_tool, Log4shell_vuln, Simplehelp_tool, 🎯Victims: Beyondtrust customers, Enterprise networks 🏭Industry: Government, Iot 🌐Geo: Polish, Chinese 🔓CVEs: CVE-2025-1094 \[[Vulners](https://vulners.com/cve/CVE-2025-1094)] - CVSS V3.1: *8.1*, - Vulners: Exploitation: True CVE-2026-1731 \[[Vulners](https://vulners.com/cve/CVE-2026-1731)] - CVSS V3.1: *9.9*, - Vulners: Exploitation: Unknown CVE-2024-12356 \[[Vulners](https://vulners.com/cve/CVE-2024-12356)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - beyondtrust privileged_remote_access (le24.3.1) - beyondtrust remote_support (le24.3.1) 🤖LLM extracted TTPs:` T1046, T1078, T1090, T1110, T1190, T1590, T1595, T1595.001 🧨IOCs: - IP: 1 💽Software: Slack, Linux, MOVEit, PostgreSQL #threatreport: CVE-2026-1731 represents a significant security vulnerability in BeyondTrust Remote Support and Privileged Remote Access servers, characterized as an OS command injection flaw with a high severity score of 9.9 (CVSS v4). The vulnerability allows unauthenticated attackers to execute arbitrary commands without requiring user interaction, making it particularly easy to exploit due to its low complexity. Recent reconnaissance activities indicate that a single IP address associated with a commercial VPN service has been responsible for approximately 86% of these probing sessions. This identified actor has been active since 2023 and has rapidly incorporated checks for CVE-2026-1731 into its operational toolkit. Interestingly, the reconnaissance is primarily focused on non-standard ports rather than the default port 443, which suggests that the threat actors are aware that many organizations configure BeyondTrust deployments to use alternative ports as a security measure. Technical analysis of the scanning sessions has uncovered JA4+ fingerprints that indicate the use of shared tooling, leveraging VPN tunneling evidenced by distinct network characteristics. The majority of sessions display a Linux stack at the TCP layer, with one dominant scanner reporting a maximum segment size (MSS) of 1358—indicative of VPN encapsulation. Furthermore, the observed HTTP traffic utilizes two different exploit tools: a lightweight version and a more complex variant, neither of which correlate with known applications in existing databases. Additionally, the actors behind these reconnaissance efforts are not exclusively targeting BeyondTrust. Their activity profile suggests they are simultaneously probing for vulnerabilities in a range of other products, including SonicWall, MOVEit Transfer, Log4j, and Sophos firewalls, alongside conducting brute force attacks on SSH and testing for default credentials in IoT devices. Some of these actors employ out-of-band callback techniques to verify vulnerabilities before executing payloads. The involvement of BeyondTrust's remote access tools in managing privileged network access highlights the critical nature of this vulnerability. Successful exploitation could grant attackers substantial access to enterprise networks. The emergence of CVE-2026-1731 follows a recognizable trend: once disclosed, proof of concept (PoC) exploits are quickly developed, leading to swift reconnaissance actions aimed at identifying vulnerable systems. Such patterns have previously resulted in successful breaches, underscoring the urgency for rapid mitigation efforts in the face of this vulnerability.
Post summary
The report highlights that reconnaissance for the high‑severity OS command injection CVE‑2026‑1731 has begun, with PoC likely developed, but no active exploitation or patch information has yet been confirmed.
