CVE-2026-40138Patch(beyondtrust / privileged_remote_access)

MEDIUMCVSS 8.1 · HIGH

Exploitation observed; activity peaked at 15 mentions and remains active

Immediate actions

  • Patch beyondtrust privileged_remote_access systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication data may allow a network-positioned attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • privileged_remote_access
  • remote_support

Threat summary

  • Active exploitation appears in 3 classified signals
  • Patch or workaround signal is available
  • 29 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • Patch or workaround mentioned in 14 signals
  • Technical details provided in 25 signals
  • Disclosure: 9 classified signals
  • General: 4 classified signals
  • Peaked 6d ago at 15 mentions (2026-07-07); latest day: 1
  • 29 total mentions across 8 days

Affected systems

Products
privileged_remote_accessremote_support

Deep dive

Activity timeline29 mentions / 8d
0481115Mentions · 2026-07-06: 2Mentions · 2026-07-07: 15Mentions · 2026-07-08: 2Mentions · 2026-07-09: 2Mentions · 2026-07-10: 1Mentions · 2026-07-23: 5Mentions · 2026-08-02: 1Mentions · 2026-08-05: 1Active Exploitation · 2026-07-07: 2Active Exploitation · 2026-07-23: 1Patch / Workaround · 2026-07-06: 1Patch / Workaround · 2026-07-07: 9Patch / Workaround · 2026-07-08: 1Patch / Workaround · 2026-07-09: 2Patch / Workaround · 2026-08-05: 1Technical Details · 2026-07-06: 1Technical Details · 2026-07-07: 13Technical Details · 2026-07-08: 2Technical Details · 2026-07-09: 2Technical Details · 2026-07-10: 1Technical Details · 2026-07-23: 4Technical Details · 2026-08-02: 1Technical Details · 2026-08-05: 107-0607-0707-0807-0907-1007-2308-0208-05
Signal classification4 categories
Patch
1344.8%
Disclosure
931.0%
General
413.8%
Active Exploitation
310.3%
Referenced assets17 URLs
Classification over time
DateTotalLabels
2026-07-062
Disclosure1Patch1
2026-07-0715
Active Exploitation2Disclosure4General1Patch8
2026-07-082
Disclosure1Patch1
2026-07-092
Patch2
2026-07-101
General1
2026-07-235
Active Exploitation1Disclosure3General1
2026-08-021
General1
2026-08-051
Patch1
Full discourse20 posts
  • Dark Web Informer@DarkWebInformer
    Disclosure

    🚨 Pre-Auth Access-Control Bypass in BeyondTrust Remote Support and PRA (CVE-2026-40138) https://darkwebinformer.com/pre-auth-access-control-bypass-in-beyondtrust-remote-support-and-pra-cve-2026-40138/

    Post summary

    The linked article announces a pre‑authentication access‑control bypass (CVE-2026‑40138) in BeyondTrust Remote Support, but does not provide PoC, exploitation details, or mitigation information.

    1110501911.0K
    233.2K followersView on X
  • ZoomEye@zoomeye_team
    General

    🚨 CVE-2026-40138: Critical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access Critical Vulnerability Alert! BeyondTrust is affected by CVE-2026-40138. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://darkeye.org/vuln/cve/CVE-2026-40138 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-40138" Search Dork: app="BeyondTrust" Exposure: 1 instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJCZXlvbmRUcnVzdCI=&t=all&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260707 #Infosec #CyberSecurity #ZoomEye #DarkEye

    Post summary

    The tweet alerts that CVE-2026-40138 affects BeyondTrust, provides external links for full analysis and search resources, but lacks details on exploitation, patches, or technical specifics.

    11003654.8K
    12.7K followersView on X
  • GovCERT.CZ@GOVCERT_CZ
    Disclosure

    🚨 Upozorňujeme na zranitelnosti v BeyondTrust Remote Support a Privileged Remote Access. V produktech RS a PRA byly identifikovány pre-autentizační chyby v autentizačním subsystému (CVE-2026-40138, CVE-2026-40139) způsobené nedostatečnou validací autentizačních dat a požadavků, které mohou umožnit neautentizovanému útočníkovi v síti obejít přístupové kontroly a získat neoprávněný přístup k zařízení včetně účtů s vyššími oprávněními; zneužitelnost těchto dvou chyb je podmíněna specifickou konfigurací autentizace. Zranitelnost CVE-2026-40140 vyplývá z nedostatečné validace vstupu od klienta a může vést k vyvolání stavu DoS, čímž může být ovlivněna dostupnost systému. Zranitelnost CVE-2026-40141 v komponentě webové aplikace způsobená nedostatečnou validací vstupů může autorizovanému útočníkovi s omezenými právy umožnit přístup k neautorizovaným zdrojům nebo datům; její zneužití je omezeno na účty se specifickými oprávněními. Celkově mohou chyby vést k obcházení autentizace, eskalaci přístupů, narušení integrity systému i dostupnosti služby. 📌Doporučujeme aktualizovat na Remote Support RS 25.3.3 a vyšší a Privileged Remote Access PRA 25.3.3 a vyšší.

    Post summary

    The text discloses four CVEs affecting BeyondTrust Remote Support and Privileged Remote Access, describing pre‑authentication and input‑validation weaknesses that could allow unauthenticated access, privilege escalation, or DoS, and recommends patching to version 25.3.3 or later.

    040711.1K
    4.3K followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Disclosure

    Critical BeyondTrust Authentication Flaws Expose Remote Support Appliances to Attacks https://gbhackers.com/critical-beyondtrust-authentication-flaws/ 『(直訳) CVE-2026-40138 – 重大度:クリティカル(CVSS 9.2):RSおよびPRAにおける不適切な認証(CWE-287)により、認証されていない攻撃者が特定の構成下でアクセス制御を回避し、昇格されたアクセス権を取得できる可能性があります。 CVE-2026-40139 – 重大度:CVSS 9.2:リモートサポートにおける認証処理の欠陥(CWE-287)により、リモート攻撃者が認証を回避して特権アカウントにアクセスできる可能性があります。 CVE-2026-40140 – 高(CVSS 8.7):制御不能なリソース消費(CWE-400)により、認証されていない攻撃者がサービス拒否状態を引き起こし、アプライアンスの可用性に影響を与える可能性があります。 CVE-2026-40141 – 高(CVSS 8.5):不適切な入力無効化(CWE-943)により、認証済みの権限の低いユーザーが不正なデータやリソースにアクセスできる可能性があります。』

    Post summary

    The article announces four new BeyondTrust authentication flaws, detailing their severity and technical nature, but does not provide PoC, exploit code, or evidence of active exploitation.

    000431.4K
    11.8K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    BeyondTrust patched a critical pre-authentication vulnerability (CVE-2026-40138, CVE-2026-40139, CVE-2026-40140). Update Remote Support instances now. #BeyondTrust #Vulnerability #CVE202640138 #CyberSecurity #RemoteSupport http://securityonline.info/cve-2026-40138-beyondtrust-pre-authentication-vulnerability/

    Post summary

    BeyondTrust has released patches for three critical pre-authentication CVEs affecting Remote Support; updates are required for affected instances.

    00051689
    12.9K followersView on X
  • SOCRadar®@socradar
    Patch

    Pre-auth flaws on remote access systems? Say goodbye to your quiet afternoon. 🚨 BeyondTrust just patched 4 RS/PRA vulns, including two critical pre-auth bugs (CVE-2026-40138 & CVE-2026-40139). Running self-hosted? Patch your internet-facing systems ASAP to mitigate the risk. https://hubs.la/Q04nKtML0 #BeyondTrust #CyberSecurity #VulnerabilityManagement

    Post summary

    The tweet announces that BeyondTrust has patched two critical pre‑authentication vulnerabilities (CVE‑2026‑40138 and CVE‑2026‑40139) and urges users to apply the fix immediately.

    00021720
    7.1K followersView on X
  • cyber_updates_365@CyberUpdates365
    Patch

    Security Alert ⚠️ BeyondTrust fixes critical CVSS 9.2 pre-auth vulnerabilities hitting Remote Support and Privileged Remote Access tools. Full analysis: 👇 https://cyberupdates365.com/beyondtrust-cve-2026-40138-40139-auth-bypass/ #ITAdmin #SysAdmin #PatchNow #latest

    Post summary

    BeyondTrust has released a patch addressing CVSS 9.2 pre‑authentication vulnerabilities in its Remote Support and Privileged Remote Access tools; the tweet provides no evidence of active exploitation or PoC, but confirms the availability of a fix.

    0003052
    16 followersView on X
  • Clone Systems@CloneSystemsInc
    Patch

    BeyondTrust has released security updates for multiple vulnerabilities affecting Remote Support and Privileged Remote Access products. The flaws include CVE-2026-40138, CVE-2026-40139, CVE-2026-40140, and CVE-2026-40141, with severity scores reaching as high as 9.9. Successful exploitation could allow attackers to bypass access controls, gain unauthorized access, trigger denial of service conditions, or access resources and data beyond their authorized scope. For organizations using remote support or privileged access tools, this is not a patch to delay. These systems often sit close to sensitive administrative workflows, which makes them high value targets when vulnerabilities are left open. Affected users should update BeyondTrust Remote Support and BeyondTrust Privileged Remote Access to version 25.3.3 or later immediately. Privileged access tools are supposed to protect the keys to the kingdom. Make sure the lock itself is not the weak point. #BeyondTrust #PrivilegedAccessManagement #RemoteSupport #CVE202640138 #CVE202640139 #CVE202640140 #CVE202640141 #VulnerabilityManagement #PatchManagement #CyberRisk

    Post summary

    BeyondTrust issued high‑severity security patches for CVE‑2026‑40138 through CVE‑2026‑40141, urging users to update to version 25.3.3 or newer to remediate the remote‑support vulnerabilities.

    0002061
    259 followersView on X
  • 中島佑允(YusukeNakajima)@nakajimeeee
    Patch

    【脆弱性管理】BeyondTrustのリモートアクセス製品に認証バイパスの重大欠陥4件——過去に実被害があった製品ラインに再び高深刻度CVE BeyondTrustは、Remote Support(RS)およびPrivileged Remote Access(PRA)に存在する4件の脆弱性を修正したセキュリティアドバイザリを公開した。うち2件が認証前に悪用可能な重大欠陥であり、特定の認証設定が有効な環境では未認証の攻撃者が管理者権限を含むアカウントへ不正アクセス可能となる。 CVE-2026-40138(CVSS 9.2)はRS・PRA双方の認証サブシステムにおける認証データ検証不備、CVE-2026-40139(CVSS 9.2)はRSの認証リクエスト処理不備で、いずれも特定の認証設定が前提条件となる。CVE-2026-40140(CVSS 8.7)はネットワーク通信サブシステムへの入力検証不備によるDoS、CVE-2026-40141(CVSS 8.5)はRS・PRAのWebアプリコンポーネントにおける限定権限アカウントによる認可範囲外アクセスだ。BeyondTrustによれば、これらはClaude Opus 4.8を含むAIモデルと自社研究ツールを活用した内部セキュリティ評価で発見された。現時点で野外での悪用は確認されていない。 ただし、同製品ラインにおけるCVE-2024-12356およびCVE-2026-1731は過去にWebシェル・バックドア展開に実際に悪用されており、攻撃者の高い関心を受け続ける製品であることを踏まえれば、RS 25.3.3・PRA 25.3.3への早急なアップデートが求められる。 https://thehackernews.com/2026/07/beyondtrust-patches-critical-auth.html

    Post summary

    BeyondTrust released a security advisory fixing four critical authentication bypass flaws in its Remote Support and Privileged Remote Access products, detailing CVSS scores and vulnerability specifics while urging users to update—no evidence of wild exploitation has been reported.

    00020517
    3.0K followersView on X
  • kokumօtօ@__kokumoto
    Disclosure

    【また君か】遠隔サポート製品BeyondTrust Remote Support/Privileged Remote Accessに無認証でアクセスが可能な重大(Critical)な脆弱性。CVE-2026-40138とCVE-2026-40139はCVSSスコア9.2で、不正形式の認証リクエストによる不正アクセス。設定条件あり。 https://securityonline.info/cve-2026-40138-beyondtrust-pre-authentication-vulnerability/

    Post summary

    BeyondTrust Remote Support/Privileged Remote Access has two critical CVEs permitting unauthenticated access through malformed authentication requests, detailed with CVSS scores and configuration conditions, but no PoC or exploit code is referenced.

    00011791
    7.6K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    05:25 UTC: Thread live on @lyrie_ai. 0day Intel: 🚨 CVE-2026-40138: Critical Pre-Authentication Vulnerability in BeyondTrust Remo

    Post summary

    The tweet announces a new critical pre‑authentication vulnerability (CVE‑2026‑40138) in BeyondTrust Remote Management without providing PoC, exploit details, or patch information.

    1000037
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    05:22 UTC: GPT-5 enrichment complete. 60 words. 1 citations. 0day Intel: 🚨 CVE-2026-40138: Critical Pre-Authentication Vulnerability in BeyondTrust Remo

    Post summary

    The message merely lists a new CVE as a 0-day with a brief description, lacking technical details, proof of concept, or exploitation context.

    1000034
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    08:11 UTC: First exploit attempt in the wild. 0day Intel: 🚨 CVE-2026-40138: Critical Pre-Authentication Vulnerability in BeyondTrust Remo

    Post summary

    A first exploit attempt has been observed in the wild for CVE-2026-40138, a critical pre‑authentication vulnerability in BeyondTrust. No PoC, exploit code, or patch has been disclosed yet.

    1000046
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    05:11 UTC: CVE-2026-40138 disclosed. 🚨 CVE-2026-40138: Critical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access

    Post summary

    The tweet announces the disclosure of CVE-2026-40138, describing it as a critical pre‑authentication vulnerability in BeyondTrust Remote Support and Privileged Remote Access.

    1000050
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    05:14 UTC: Lyrie Sentinel flagged it. 0day Intel: 🚨 CVE-2026-40138: Critical Pre-Authentication Vulnerability in BeyondTrust Remo

    Post summary

    CVE‑2026‑40138, a pre‑authentication vulnerability in BeyondTrust, has been identified and announced, but no proof‑of‑concept, exploit code, or patch details are provided.

    1000037
    326 followersView on X
  • ThreatWire@ThreatWire_
    Disclosure

    🚨 CVE-2026-40138: A pre-authentication access control bypass vulnerability has been disclosed in BeyondTrust Remote Support and PRA, potentially allowing unauthorized access. #CyberSecurity #CVE #BeyondTrust #ThreatWire https://t.co/Pc97bCGrk2

    Post summary

    A pre‑authentication access‑control bypass vulnerability (CVE‑2026‑40138) has been disclosed for BeyondTrust Remote Support and PRA, but no PoC, exploit, or patch details are provided.

    0001090
    65 followersView on X
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    Disclosure

    CVE-2026-40138 BeyondTrust PRA Improper authentication could allow bypass of access controls in privileged remote access environments where affected non-default configuration is enabled Analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-07-06/TIER_2_CVE-2026-40138.md #CyberSecurity #IdentitySecurity #VulnerabilityManagement

    Post summary

    The post announces CVE-2026-40138 in BeyondTrust PRA, describing an authentication flaw that permits bypassing access controls under certain configurations, without indicating exploitation, PoC, or patch details.

    0001063
    56 followersView on X
  • Cybersecurity News Alerts@secureblognews
    Patch

    🚨 CRITICAL ALERT: BeyondTrust Remote Support & PRA appliances hit with two pre-authentication bypass flaws (CVE-2026-40138 & CVE-2026-40139)! 🛑 Patch & fix guide 👇 https://cyberupdates365.com/beyondtrust-cve-2026-40138-40139-auth-bypass/ #CyberSecurity #InfoSec #Cybergate #latestnews

    Post summary

    The tweet warns of two pre‑authentication bypass flaws (CVE‑2026‑40138 & CVE‑2026‑40139) in BeyondTrust Remote Support & PRA appliances and directs users to a patch & fix guide.

    0001089
    29 followersView on X
  • SecEngCyGy@snypet86
    Patch

    BeyondTrust RS/PRA BT26-03: critical pre-auth access-control flaws (CVE-2026-40138/40139). Can bypass appliance controls toward elevated accounts. Patch RS/PRA this week; limit management exposure. https://www.beyondtrust.com/trust-center/security-advisories/bt26-03 #CyberSecurity

    Post summary

    BeyondTrust announced two critical pre‑authentication access‑control flaws (CVE‑2026‑40138/40139) and is issuing a patch this week to address them.

    0000048
    23 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-40138: BeyondTrust Remote Support and Privileged Remote Access Authentication Bypass - What It Means for Your Business and How to Respond https://hubs.li/Q04rBj3b0

    Post summary

    The provided text announces CVE‑2026‑40138 as an authentication bypass in BeyondTrust products, noting potential business impact, but offers no PoCs, exploits, or patch info.

    0000035
    32 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appbeyondtrustprivileged_remote_access---
Appbeyondtrustremote_support---

Explore more