CVE-2026-1731Active Exploitation(beyondtrust / privileged_remote_access)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 50 mentions and remains active

Immediate actions

  • Patch beyondtrust privileged_remote_access systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-02-16. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-78

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • privileged_remote_access
  • remote_support

Threat summary

  • Active exploitation appears in 252 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 442 mentions across 56 observed days

What's happening

  • Active exploitation reported across 252 signals
  • Exploit tool or code specified in 41 signals
  • PoC mentioned or linked in 95 signals
  • Patch or workaround mentioned in 158 signals
  • Technical details provided in 276 signals
  • General: 58 classified signals
  • Peaked 41d ago at 50 mentions (2026-02-20); latest day: 1
  • 442 total mentions across 56 days

Affected systems

Products
privileged_remote_accessremote_support

Deep dive

Activity timeline442 mentions / 56d
013253850Mentions · 2026-02-06: 2Mentions · 2026-02-07: 7Mentions · 2026-02-08: 3Mentions · 2026-02-09: 38Mentions · 2026-02-10: 31Mentions · 2026-02-11: 9Mentions · 2026-02-12: 8Mentions · 2026-02-13: 46Mentions · 2026-02-14: 37Mentions · 2026-02-15: 19Mentions · 2026-02-16: 30Mentions · 2026-02-17: 12Mentions · 2026-02-18: 8Mentions · 2026-02-19: 13Mentions · 2026-02-20: 50Mentions · 2026-02-21: 3Mentions · 2026-02-22: 9Mentions · 2026-02-23: 20Mentions · 2026-02-24: 11Mentions · 2026-02-25: 16Mentions · 2026-02-26: 8Mentions · 2026-02-27: 4Mentions · 2026-02-28: 2Mentions · 2026-03-02: 1Mentions · 2026-03-03: 1Mentions · 2026-03-04: 2Mentions · 2026-03-05: 2Mentions · 2026-03-06: 3Mentions · 2026-03-08: 2Mentions · 2026-03-10: 1Mentions · 2026-03-11: 1Mentions · 2026-03-13: 4Mentions · 2026-03-14: 1Mentions · 2026-03-15: 1Mentions · 2026-03-18: 1Mentions · 2026-03-23: 1Mentions · 2026-03-24: 1Mentions · 2026-04-03: 2Mentions · 2026-04-11: 1Mentions · 2026-04-15: 2Mentions · 2026-04-17: 1Mentions · 2026-04-18: 1Mentions · 2026-04-19: 2Mentions · 2026-04-21: 3Mentions · 2026-04-22: 2Mentions · 2026-04-23: 1Mentions · 2026-04-25: 1Mentions · 2026-04-30: 1Mentions · 2026-05-05: 3Mentions · 2026-05-12: 1Mentions · 2026-05-24: 1Mentions · 2026-06-20: 3Mentions · 2026-08-20: 1Mentions · 2026-09-28: 1Mentions · 2026-10-01: 6Mentions · 2026-10-02: 1PoC Mentioned / Linked · 2026-02-07: 1PoC Mentioned / Linked · 2026-02-10: 4PoC Mentioned / Linked · 2026-02-11: 4PoC Mentioned / Linked · 2026-02-12: 1PoC Mentioned / Linked · 2026-02-13: 23PoC Mentioned / Linked · 2026-02-14: 13PoC Mentioned / Linked · 2026-02-15: 10PoC Mentioned / Linked · 2026-02-16: 9PoC Mentioned / Linked · 2026-02-17: 1PoC Mentioned / Linked · 2026-02-18: 1PoC Mentioned / Linked · 2026-02-19: 7PoC Mentioned / Linked · 2026-02-20: 5PoC Mentioned / Linked · 2026-02-22: 1PoC Mentioned / Linked · 2026-02-23: 4PoC Mentioned / Linked · 2026-02-24: 1PoC Mentioned / Linked · 2026-02-25: 1PoC Mentioned / Linked · 2026-02-27: 1PoC Mentioned / Linked · 2026-03-04: 1PoC Mentioned / Linked · 2026-03-08: 1PoC Mentioned / Linked · 2026-03-10: 1PoC Mentioned / Linked · 2026-03-23: 1PoC Mentioned / Linked · 2026-04-11: 1PoC Mentioned / Linked · 2026-04-18: 1PoC Mentioned / Linked · 2026-04-19: 1PoC Mentioned / Linked · 2026-05-05: 1Exploit Tool / Code · 2026-02-10: 2Exploit Tool / Code · 2026-02-11: 2Exploit Tool / Code · 2026-02-12: 2Exploit Tool / Code · 2026-02-13: 4Exploit Tool / Code · 2026-02-15: 3Exploit Tool / Code · 2026-02-19: 2Exploit Tool / Code · 2026-02-20: 12Exploit Tool / Code · 2026-02-22: 1Exploit Tool / Code · 2026-02-23: 4Exploit Tool / Code · 2026-02-24: 1Exploit Tool / Code · 2026-02-27: 1Exploit Tool / Code · 2026-02-28: 1Exploit Tool / Code · 2026-03-04: 1Exploit Tool / Code · 2026-03-05: 1Exploit Tool / Code · 2026-03-08: 1Exploit Tool / Code · 2026-03-23: 1Exploit Tool / Code · 2026-04-17: 1Exploit Tool / Code · 2026-05-12: 1Active Exploitation · 2026-02-09: 1Active Exploitation · 2026-02-10: 1Active Exploitation · 2026-02-12: 4Active Exploitation · 2026-02-13: 39Active Exploitation · 2026-02-14: 21Active Exploitation · 2026-02-15: 13Active Exploitation · 2026-02-16: 19Active Exploitation · 2026-02-17: 9Active Exploitation · 2026-02-18: 7Active Exploitation · 2026-02-19: 9Active Exploitation · 2026-02-20: 45Active Exploitation · 2026-02-21: 2Active Exploitation · 2026-02-22: 7Active Exploitation · 2026-02-23: 18Active Exploitation · 2026-02-24: 7Active Exploitation · 2026-02-25: 13Active Exploitation · 2026-02-26: 6Active Exploitation · 2026-02-27: 2Active Exploitation · 2026-02-28: 1Active Exploitation · 2026-03-02: 1Active Exploitation · 2026-03-03: 1Active Exploitation · 2026-03-05: 2Active Exploitation · 2026-03-06: 2Active Exploitation · 2026-03-08: 1Active Exploitation · 2026-03-13: 1Active Exploitation · 2026-03-14: 1Active Exploitation · 2026-03-18: 1Active Exploitation · 2026-04-03: 1Active Exploitation · 2026-04-11: 1Active Exploitation · 2026-04-17: 1Active Exploitation · 2026-04-18: 1Active Exploitation · 2026-04-19: 2Active Exploitation · 2026-04-21: 3Active Exploitation · 2026-04-22: 1Active Exploitation · 2026-04-25: 1Active Exploitation · 2026-04-30: 1Active Exploitation · 2026-05-05: 2Active Exploitation · 2026-05-12: 1Active Exploitation · 2026-06-20: 1Active Exploitation · 2026-08-20: 1Active Exploitation · 2026-10-01: 1Patch / Workaround · 2026-02-07: 4Patch / Workaround · 2026-02-08: 1Patch / Workaround · 2026-02-09: 21Patch / Workaround · 2026-02-10: 18Patch / Workaround · 2026-02-11: 3Patch / Workaround · 2026-02-12: 3Patch / Workaround · 2026-02-13: 22Patch / Workaround · 2026-02-14: 14Patch / Workaround · 2026-02-15: 7Patch / Workaround · 2026-02-16: 9Patch / Workaround · 2026-02-17: 7Patch / Workaround · 2026-02-18: 4Patch / Workaround · 2026-02-19: 3Patch / Workaround · 2026-02-20: 14Patch / Workaround · 2026-02-21: 1Patch / Workaround · 2026-02-22: 2Patch / Workaround · 2026-02-23: 3Patch / Workaround · 2026-02-24: 5Patch / Workaround · 2026-02-25: 5Patch / Workaround · 2026-02-26: 2Patch / Workaround · 2026-03-06: 1Patch / Workaround · 2026-03-08: 1Patch / Workaround · 2026-03-13: 2Patch / Workaround · 2026-03-14: 1Patch / Workaround · 2026-03-18: 1Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-06-20: 2Technical Details · 2026-02-06: 2Technical Details · 2026-02-07: 4Technical Details · 2026-02-08: 2Technical Details · 2026-02-09: 36Technical Details · 2026-02-10: 26Technical Details · 2026-02-11: 7Technical Details · 2026-02-12: 3Technical Details · 2026-02-13: 29Technical Details · 2026-02-14: 23Technical Details · 2026-02-15: 13Technical Details · 2026-02-16: 17Technical Details · 2026-02-17: 10Technical Details · 2026-02-18: 7Technical Details · 2026-02-19: 5Technical Details · 2026-02-20: 29Technical Details · 2026-02-21: 2Technical Details · 2026-02-22: 5Technical Details · 2026-02-23: 8Technical Details · 2026-02-24: 5Technical Details · 2026-02-25: 8Technical Details · 2026-02-26: 5Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-04: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 2Technical Details · 2026-03-08: 2Technical Details · 2026-03-10: 1Technical Details · 2026-03-13: 4Technical Details · 2026-03-14: 1Technical Details · 2026-03-15: 1Technical Details · 2026-03-18: 1Technical Details · 2026-03-23: 1Technical Details · 2026-03-24: 1Technical Details · 2026-04-03: 1Technical Details · 2026-04-11: 1Technical Details · 2026-04-18: 1Technical Details · 2026-04-19: 1Technical Details · 2026-04-21: 2Technical Details · 2026-04-22: 1Technical Details · 2026-04-25: 1Technical Details · 2026-04-30: 1Technical Details · 2026-05-12: 1Technical Details · 2026-06-20: 1Technical Details · 2026-10-01: 102-0602-1102-1602-2102-2603-0403-1103-2304-1704-2305-2410-02
Signal classification7 categories
Active Exploitation
24255.6%
Patch
6915.9%
General
5813.3%
Disclosure
4410.1%
PoC
133.0%
Exploit
81.8%
Referenced assets290 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-062
Disclosure2
2026-02-077
General3Patch4
2026-02-083
Disclosure2General1
2026-02-0938
Active Exploitation1Disclosure14General2Patch21
2026-02-1031
Active Exploitation1Disclosure4Exploit1General6Patch17PoC2
2026-02-119
Disclosure2General1Patch3PoC3
2026-02-128
Active Exploitation3Exploit1General1Patch2PoC1
2026-02-1346
Active Exploitation39General3Patch2PoC2
2026-02-1437
Active Exploitation18Disclosure1General10Patch6PoC2
2026-02-1519
Active Exploitation13Disclosure2General1Patch2PoC1
2026-02-1630
Active Exploitation15Disclo1Disclosure7Exploit1General4Patch2
2026-02-1712
Active Exploitation9Disclosure1General2
2026-02-188
Active Exploitation7Disclosure1
2026-02-1913
Active Exploitation9Disclosure1General1Patch1PoC1
2026-02-2050
Active Exploitation43Disclosure1Exploit1General3Patch2
2026-02-213
Active Exploitation2General1
2026-02-229
Active Exploitation7General2
2026-02-2320
Active Exploitation18General2
2026-02-2411
Active Exploitation7Disclosure1General1Patch2
2026-02-2516
Active Exploitation13Disclosure1General1Patch1
2026-02-268
Active Exploitation6General2
2026-02-274
Active Exploitation2Exploit1General1
2026-02-282
Active Exploitation1Exploit1
2026-03-021
Active Exploitation1
2026-03-031
Active Exploitation1
2026-03-042
Exploit1General1
2026-03-052
Active Exploitation2
2026-03-063
Active Exploitation2General1
2026-03-082
Active Exploitation1Patch1
2026-03-101
Exploit1
2026-03-111
General1
2026-03-134
Active Exploitation1Disclosure1Patch2
2026-03-141
Active Exploitation1
2026-03-151
Disclosure1
2026-03-181
Active Exploitation1
2026-03-231
PoC1
2026-03-241
Disclosure1
2026-04-032
Active Exploitation1General1
2026-04-111
Active Exploitation1
2026-04-152
General2
2026-04-171
Active Exploitation1
2026-04-181
Active Exploitation1
2026-04-192
Active Exploitation2
2026-04-213
Active Exploitation3
2026-04-222
Active Exploitation1Patch1
2026-04-231
Disclosure1
2026-04-251
Active Exploitation1
2026-04-301
Active Exploitation1
2026-05-053
Active Exploitation2General1
2026-05-121
Active Exploitation1
2026-05-241
General1
2026-06-203
Active Exploitation1General2
2026-08-201
Active Exploitation1
2026-10-016
Active Exploitation1
Full discourse20 posts
  • Ryan Dewhurst@ethicalhack3r
    Active Exploitation

    Overnight we observed first in-the-wild exploitation of BeyondTrust across our global sensors. Attackers are abusing get_portal_info to extract the x-ns-company value before establishing a WebSocket channel. CVE-2026-1731 If not patched, assume compromise.

    Post summary

    First in-the-wild exploitation of BeyondTrust CVE-2026-1731 observed globally; attackers abuse get_portal_info to extract the x-ns-company header and then open a WebSocket channel.

    453332111945.7K
    21.0K followersView on X
  • Hacktron AI@HacktronAI
    Patch

    🚨 CVE-2026-1731 🚨 Our team discovered a critical pre-auth RCE affecting BeyondTrust Remote Support & Privileged Remote Access. SaaS/Cloud instances have been patched. If you're running self-hosted deployments, apply the patches immediately. More info in the comments. https://t.co/I66eJPseRu

    Post summary

    A critical pre‑authentication RCE in BeyondTrust Remote Support & Privileged Remote Access (CVE‑2026‑1731) has been discovered; SaaS/Cloud instances are patched and self‑hosted deployments are urged to apply patches immediately.

    36542517834.3K
    3.1K followersView on X
  • Geekboy@emgeekboy
    Patch

    Scan for CVE-2026-1731 (BeyondTrust Remote Support - Unauthenticated WebSocket RCE) using @pdnuclei If you are using the @pdiscoveryio Cloud with real-time scan enabled, scan alerts are already out. Nuclei Template - https://cloud.projectdiscovery.io/library/CVE-2026-1731 Security Advisory - https://www.beyondtrust.com/trust-center/security-advisories/bt26-02

    Post summary

    The post alerts readers to scan for CVE‑2026‑1731 using a Nuclei template and directs them to a vendor advisory that likely contains patching or mitigation steps.

    23711919417.0K
    25.8K followersView on X
  • Florian Roth ⚡️@cyb3rops
    General

    Forget the Microsoft Notpad RCE(?) CVE-2026-1731 Look at the BeyondTrust Remote Support Pre-Auth RCE CVE-2026-1731

    Post summary

    The post merely redirects attention from a supposed Microsoft Notepad RCE claim to the BeyondTrust Remote Support pre‑authentication RCE associated with CVE‑2026‑1731, without providing additional details.

    63401956625.9K
    215.8K followersView on X
  • Bipin Jitiya@win3zz
    PoC

    CVE-2026-1731 BeyondTrust Remote Support Pre-Auth RCE PoC 👇 https://github.com/win3zz/CVE-2026-1731 https://t.co/r80tQy9kTM

    Post summary

    The tweet announces a proof‑of‑concept for CVE‑2026‑1731, linking to GitHub code, and describes a pre‑authentication RCE in BeyondTrust Remote Support, without mentioning patches or active exploitation.

    24001697712.1K
    7.8K followersView on X
  • Stephen Fewer@stephenfewer
    PoC

    We just published our @rapid7 analysis of CVE-2026-1731, a critical command injection affecting BeyondTrust Privileged Remote Access (PRA) & Remote Support (RS). Unauthenticated RCE, with a root cause due to Bash arithmetic evaluation. Analysis/PoC here: https://attackerkb.com/topics/jNMBccstay/cve-2026-1731/rapid7-analysis

    Post summary

    Rapid7 released an analysis of CVE-2026-1731, highlighting a critical command injection that enables unauthenticated remote code execution, and provided a PoC via the linked resource.

    33421224025.3K
    9.6K followersView on X
  • Hunter@HunterMapping
    Disclosure

    🚨Alert🚨 CVE-2026-1731 (CVSS 9.9): Remote code execution in Remote Support (RS) and Privileged Remote Access (PRA) 📊 2.5M+ Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22BeyondTrust%20Privileged%20Remote%20Access%22%7C%7Cproduct.name%3D%22BeyondTrust%20Remote%20Support%22 👇Query HUNTER : http://product.name="BeyondTrust Privileged Remote Access"||http://product.name="BeyondTrust Remote Support" 📰Refer:https://www.beyondtrust.com/trust-center/security-advisories/bt26-02 #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    The post announces CVE-2026-1731, a high‑severity remote code execution vulnerability in BeyondTrust Remote Support and Privileged Remote Access, noting its CVSS score of 9.9 and referencing a vendor advisory and a search of affected services.

    2281104328.3K
    25.4K followersView on X
  • Harsh Jaiswal@rootxharsh
    PoC

    The exploit for CVE-2026-1731 is out. The APT of CVE-2026-1281 missed a major target 😅. Props to watchTowr for the blog on it. The moment I read it, my instinct said there had to be a variant in remote support, given how heavily it relies on bash scripts. @HacktronAI did the rest. Literally gave me PoC in hand. (Vibe hacking?) What surprised me was that I didn’t know this bash quirk earlier, even though I’d already run into a similar quirk in another language. Consider this a reminder: read the blogs. Always.

    Post summary

    An exploit for CVE-2026-1731 has been released and a PoC was provided, but no detailed technical info, patch, or evidence of active exploitation is presented.

    1130974514.6K
    22.1K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    Attackers are actively exploiting CVE-2026-1731 (CVSS 9.9) in BeyondTrust RS and PRA to run OS commands as the site user. Unit 42 saw web shells, VShell, Spark RAT, lateral movement, and full PostgreSQL dumps across finance, legal, tech, and healthcare. CISA confirms ransomware use. 🔗 Details → https://thehackernews.com/2026/02/beyondtrust-flaw-used-for-web-shells.html

    Post summary

    Attackers are actively abusing CVE‑2026‑1731 to deploy web shells, RATs, and ransomware, as confirmed by Unit 42 and CISA.

    236096129.3K
    1.0M followersView on X
  • CryptoCat@_CryptoCat
    Exploit

    My first @metasploit module is live! You can now exploit CVE-2026-1731 (BeyondTrust command injection) with the latest version 😎 https://t.co/YlzR3h54Q5

    Post summary

    A new Metasploit module for CVE‑2026‑1731 (BeyondTrust command injection) has been released, providing a functional exploit tool.

    3150101224.8K
    8.5K followersView on X
  • Rapid7@rapid7
    Disclosure

    🚨 On 2/6/26, #BeyondTrust disclosed a critical RCE vulnerability affecting its Remote Support (RS) and Privileged Remote Access (PRA) products. The flaw has been assigned CVE-2026-1731 and a near-maximum CVSSv4 score of 9.9. More in the Rapid7 blog: https://r-7.co/4arAjln https://t.co/Ko7Y45Q4cO

    Post summary

    BeyondTrust announced a critical RCE flaw (CVE-2026-1731) in its Remote Support and Privileged Remote Access products with a CVSSv4 score of 9.9; no PoC, exploit code, or patch details were provided in the tweet.

    9281691910.2K
    123.7K followersView on X
  • _leon_jacobs(💥)@leonjza
    PoC

    Had a case this week of a fairly secure deployment of BeyondTrust, but vulnerable to CVE-2026-1731. With basically zero egress, I implemented a timing oracle POC instead. Takes about 20 minutes to get the ls command output in this demo, but hey, it works! :D https://t.co/sjwEzr3uwo

    Post summary

    The author reports a BeyondTrust deployment vulnerable to CVE‑2026‑1731 and demonstrates a working timing‑oracle proof‑of‑concept that retrieves the ls output.

    27083258.8K
    4.7K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    Threat actors are actively exploiting CVE-2026-1731 (9.9) in BeyondTrust Remote Support & PRA. Attackers extract portal data, then open WebSocket channels to trigger unauthenticated RCE. 🔗 Read → https://thehackernews.com/2026/02/researchers-observe-in-wild.html Patches are out, but exploitation started fast.

    Post summary

    The post reports that CVE‑2026‑1731 is being actively exploited in the wild, delivering unauthenticated RCE via WebSocket in BeyondTrust Remote Support & PRA, and notes that patches are already available.

    8260691012.9K
    1.0M followersView on X
  • s1r1us (mohan)@S1r1u5_
    General

    CVE-2026-1731 Last night @rootxharsh and I were driving around Hyderabad, looking at office buildings and checking if we could RCE any of them. Every single building had a company we could potentially pwn. https://t.co/qulYzwX8L3

    Post summary

    The tweet references CVE‑2026‑1731 and indicates the user was scouting potential RCE targets, but provides no technical details, PoC, patch information, or evidence of exploitation.

    27085198.0K
    12.1K followersView on X
  • Rishi@rxerium
    General

    Nuclei template for CVE-2026-1731 👇

    Post summary

    A Nuclei detection template has been released for CVE-2026-1731, but the post does not provide any exploit, patch, or detailed vulnerability information.

    18066355.5K
    3.1K followersView on X
  • The Hacker News@TheHackersNews
    Patch

    ⚡ BeyondTrust patched pre-auth RCE (CVE-2026-1731) in Remote Support and PRA. Attackers could run OS commands via crafted requests.~11K exposed instances found. Patches released. 🔗 Versions affected, fixes → https://thehackernews.com/2026/02/beyondtrust-fixes-critical-pre-auth-rce.html

    Post summary

    BeyondTrust has released patches for CVE-2026-1731, a pre‑authentication remote code execution flaw that lets attackers execute OS commands. While 11K exposed instances were identified, no active exploitation is reported.

    22526999.5K
    1.0M followersView on X
  • Unit 42@Unit42_Intel
    Active Exploitation

    We discuss findings from exploitation of CVE-2026-1731, an RCE vuln affecting PIM/PAM platform BeyondTrust. Attackers are deploying VShell and SparkRAT backdoors. Our analysis includes the CVE's mechanism, scope of attack and historic context. https://bit.ly/4arxNwD https://t.co/JOPWt0XJVW

    Post summary

    CVE-2026-1731 is an RCE vulnerability in BeyondTrust PIM/PAM that is actively exploited by attackers deploying VShell and SparkRAT backdoors, with analysis detailing the mechanism and attack scope, but no patch or mitigation information is provided.

    416044174.3K
    66.5K followersView on X
  • Defused@DefusedCyber
    Disclosure

    🚨 A critical pre-auth RCE has been disclosed in BeyondTrust Remote Support and PRA (CVE-2026-1731, CVSS 9.9) Our intel suggests this is another websocket vuln, similar to CVE-2024-12356 🍯We have added a BeyondTrust RS honeypot stream for Defused TF 👉 https://console.defusedcyber.com/signup https://t.co/6iVgqRgbKz

    Post summary

    BeyondTrust Remote Support and PRA are affected by a pre‑authentication RCE (CVE‑2026‑1731) with a CVSS of 9.9, described as a websocket flaw similar to CVE‑2024‑12356.

    013154139.9K
    6.0K followersView on X
  • Cyber Security News@The_Cyber_News
    Active Exploitation

    ⚠️ Critical BeyondTrust Vulnerability Exploited in the Wild to Gain Full Domain Control Source: https://cybersecuritynews.com/beyondtrust-vulnerability-exploited/ A critical vulnerability tracked as CVE-2026-1731 is being actively exploited in the wild, enabling attackers to gain full domain control over affected systems. Threat actors are leveraging this flaw to execute operating system commands remotely without authentication. The flaw, discovered in self-hosted BeyondTrust deployments, allows unauthenticated attackers to run arbitrary OS commands via specially crafted HTTP requests, executing them under the site user’s privileges. #cybersecuritynews

    Post summary

    CVE-2026-1731 in BeyondTrust is being actively exploited in the wild, enabling unauthenticated attackers to run arbitrary OS commands via crafted HTTP requests, resulting in full domain takeover.

    51704963.1K
    47.0K followersView on X
  • CISA Cyber@CISACyber
    Patch

    🛡We added BeyondTrust Remote Support and Privileged Remote Access OS command injection vulnerability CVE-2026-1731 to our KEV Catalog. Apply mitigations to protect your org from cyberattacks. https://go.dhs.gov/Z3Q #Cybersecurity #InfoSec https://t.co/4ls1Yp3Xcc

    Post summary

    DHS added CVE‑2026‑1731, an OS command injection flaw, to its Known Exploited Vulnerabilities catalog and urged organizations to apply mitigations against potential attacks.

    121203877.2K
    291.8K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appbeyondtrustprivileged_remote_access---
Appbeyondtrustremote_support---

Explore more