CVE-2026-40139Patch(beyondtrust / privileged_remote_access)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 9 mentions and remains active

Immediate actions

  • Patch beyondtrust privileged_remote_access systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • privileged_remote_access
  • remote_support

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 15 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 12 signals
  • Technical details provided in 12 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 9 mentions (2026-07-07); latest day: 1
  • 15 total mentions across 5 days

Affected systems

Products
privileged_remote_accessremote_support

Deep dive

Activity timeline15 mentions / 5d
02579Mentions · 2026-07-06: 1Mentions · 2026-07-07: 9Mentions · 2026-07-08: 2Mentions · 2026-07-09: 2Mentions · 2026-08-06: 1Active Exploitation · 2026-07-07: 1Patch / Workaround · 2026-07-06: 1Patch / Workaround · 2026-07-07: 7Patch / Workaround · 2026-07-08: 2Patch / Workaround · 2026-07-09: 2Technical Details · 2026-07-06: 1Technical Details · 2026-07-07: 7Technical Details · 2026-07-08: 2Technical Details · 2026-07-09: 207-0607-0707-0807-0908-06
Signal classification4 categories
Patch
1173.3%
Disclosure
213.3%
Active Exploitation
16.7%
General
16.7%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-07-061
Patch1
2026-07-079
Active Exploitation1Disclosure2Patch6
2026-07-082
Patch2
2026-07-092
Patch2
2026-08-061
General1
Full discourse15 posts
  • GovCERT.CZ@GOVCERT_CZ
    Patch

    🚨 Upozorňujeme na zranitelnosti v BeyondTrust Remote Support a Privileged Remote Access. V produktech RS a PRA byly identifikovány pre-autentizační chyby v autentizačním subsystému (CVE-2026-40138, CVE-2026-40139) způsobené nedostatečnou validací autentizačních dat a požadavků, které mohou umožnit neautentizovanému útočníkovi v síti obejít přístupové kontroly a získat neoprávněný přístup k zařízení včetně účtů s vyššími oprávněními; zneužitelnost těchto dvou chyb je podmíněna specifickou konfigurací autentizace. Zranitelnost CVE-2026-40140 vyplývá z nedostatečné validace vstupu od klienta a může vést k vyvolání stavu DoS, čímž může být ovlivněna dostupnost systému. Zranitelnost CVE-2026-40141 v komponentě webové aplikace způsobená nedostatečnou validací vstupů může autorizovanému útočníkovi s omezenými právy umožnit přístup k neautorizovaným zdrojům nebo datům; její zneužití je omezeno na účty se specifickými oprávněními. Celkově mohou chyby vést k obcházení autentizace, eskalaci přístupů, narušení integrity systému i dostupnosti služby. 📌Doporučujeme aktualizovat na Remote Support RS 25.3.3 a vyšší a Privileged Remote Access PRA 25.3.3 a vyšší.

    Post summary

    Advisory highlighting authentication bypass and privilege escalation flaws in BeyondTrust Remote Support and Privileged Remote Access, issuing a patch recommendation to upgrade to version 25.3.3 or newer.

    040711.1K
    4.3K followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Disclosure

    Critical BeyondTrust Authentication Flaws Expose Remote Support Appliances to Attacks https://gbhackers.com/critical-beyondtrust-authentication-flaws/ 『(直訳) CVE-2026-40138 – 重大度:クリティカル(CVSS 9.2):RSおよびPRAにおける不適切な認証(CWE-287)により、認証されていない攻撃者が特定の構成下でアクセス制御を回避し、昇格されたアクセス権を取得できる可能性があります。 CVE-2026-40139 – 重大度:CVSS 9.2:リモートサポートにおける認証処理の欠陥(CWE-287)により、リモート攻撃者が認証を回避して特権アカウントにアクセスできる可能性があります。 CVE-2026-40140 – 高(CVSS 8.7):制御不能なリソース消費(CWE-400)により、認証されていない攻撃者がサービス拒否状態を引き起こし、アプライアンスの可用性に影響を与える可能性があります。 CVE-2026-40141 – 高(CVSS 8.5):不適切な入力無効化(CWE-943)により、認証済みの権限の低いユーザーが不正なデータやリソースにアクセスできる可能性があります。』

    Post summary

    The text announces four critical authentication flaws in BeyondTrust appliances, providing CVSS, CWE, and severity details, but does not include PoCs, exploits, active exploitation evidence, or mitigation guidance.

    000431.4K
    11.8K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    BeyondTrust patched a critical pre-authentication vulnerability (CVE-2026-40138, CVE-2026-40139, CVE-2026-40140). Update Remote Support instances now. #BeyondTrust #Vulnerability #CVE202640138 #CyberSecurity #RemoteSupport http://securityonline.info/cve-2026-40138-beyondtrust-pre-authentication-vulnerability/

    Post summary

    BeyondTrust has patched critical pre-authentication vulnerabilities CVE-2026-40138, 40139, and 40140, encouraging users to update Remote Support; no active exploitation or proof-of-concept details are mentioned.

    00051689
    12.9K followersView on X
  • SOCRadar®@socradar
    Patch

    Pre-auth flaws on remote access systems? Say goodbye to your quiet afternoon. 🚨 BeyondTrust just patched 4 RS/PRA vulns, including two critical pre-auth bugs (CVE-2026-40138 & CVE-2026-40139). Running self-hosted? Patch your internet-facing systems ASAP to mitigate the risk. https://hubs.la/Q04nKtML0 #BeyondTrust #CyberSecurity #VulnerabilityManagement

    Post summary

    BeyondTrust has patched two critical pre‑authentication vulnerabilities (CVE‑2026‑40138 & CVE‑2026‑40139) and urges users to apply the updates immediately.

    00021720
    7.1K followersView on X
  • Clone Systems@CloneSystemsInc
    Patch

    BeyondTrust has released security updates for multiple vulnerabilities affecting Remote Support and Privileged Remote Access products. The flaws include CVE-2026-40138, CVE-2026-40139, CVE-2026-40140, and CVE-2026-40141, with severity scores reaching as high as 9.9. Successful exploitation could allow attackers to bypass access controls, gain unauthorized access, trigger denial of service conditions, or access resources and data beyond their authorized scope. For organizations using remote support or privileged access tools, this is not a patch to delay. These systems often sit close to sensitive administrative workflows, which makes them high value targets when vulnerabilities are left open. Affected users should update BeyondTrust Remote Support and BeyondTrust Privileged Remote Access to version 25.3.3 or later immediately. Privileged access tools are supposed to protect the keys to the kingdom. Make sure the lock itself is not the weak point. #BeyondTrust #PrivilegedAccessManagement #RemoteSupport #CVE202640138 #CVE202640139 #CVE202640140 #CVE202640141 #VulnerabilityManagement #PatchManagement #CyberRisk

    Post summary

    BeyondTrust has released patches for four high‑severity CVEs (CVE‑2026‑40138 to 40141); users are urged to update to version 25.3.3 or newer to mitigate potential exploitation.

    0002061
    259 followersView on X
  • 中島佑允(YusukeNakajima)@nakajimeeee
    Patch

    【脆弱性管理】BeyondTrustのリモートアクセス製品に認証バイパスの重大欠陥4件——過去に実被害があった製品ラインに再び高深刻度CVE BeyondTrustは、Remote Support(RS)およびPrivileged Remote Access(PRA)に存在する4件の脆弱性を修正したセキュリティアドバイザリを公開した。うち2件が認証前に悪用可能な重大欠陥であり、特定の認証設定が有効な環境では未認証の攻撃者が管理者権限を含むアカウントへ不正アクセス可能となる。 CVE-2026-40138(CVSS 9.2)はRS・PRA双方の認証サブシステムにおける認証データ検証不備、CVE-2026-40139(CVSS 9.2)はRSの認証リクエスト処理不備で、いずれも特定の認証設定が前提条件となる。CVE-2026-40140(CVSS 8.7)はネットワーク通信サブシステムへの入力検証不備によるDoS、CVE-2026-40141(CVSS 8.5)はRS・PRAのWebアプリコンポーネントにおける限定権限アカウントによる認可範囲外アクセスだ。BeyondTrustによれば、これらはClaude Opus 4.8を含むAIモデルと自社研究ツールを活用した内部セキュリティ評価で発見された。現時点で野外での悪用は確認されていない。 ただし、同製品ラインにおけるCVE-2024-12356およびCVE-2026-1731は過去にWebシェル・バックドア展開に実際に悪用されており、攻撃者の高い関心を受け続ける製品であることを踏まえれば、RS 25.3.3・PRA 25.3.3への早急なアップデートが求められる。 https://thehackernews.com/2026/07/beyondtrust-patches-critical-auth.html

    Post summary

    BeyondTrust has announced patches for four critical authentication bypass and DoS vulnerabilities (CVE‑2026‑40138‑41) with high CVSS scores; no in‑the‑wild exploitation has been reported, but an update is urgently recommended.

    00020517
    3.0K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Multiple critical pre-authentication bypass vulnerabilities in #BeyondTrust Remote Support and Privileged Remote Access including #CVE-2026-40139 (CVSS: 9.2). This allows unauthenticated remote attackers to gain elevated privileges. https://ccb.belgium.be/advisories/warning-critical-vulnerabilities-beyondtrust-remote-support-and-privileged-remote-access #Patch

    Post summary

    The advisory warns of several pre‑authentication bypass vulnerabilities in BeyondTrust Remote Support and Privileged Remote Access, providing CVE details and stressing the availability of patches.

    00010325
    7.2K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - BeyondTrust Remote Support Pre-Auth Bypass (CVE-2026-40139) An improper-authentication flaw in the auth subsystem of BeyondTrust Remote Support lets an unauthenticated remote attacker bypass access controls and gain unauthorized access to the appliance - including elevated-privilege accounts - by abusing improper processing of authentication requests. Exploitation requires a specific authentication configuration to be enabled. Because these appliances broker privileged remote and support sessions, an auth bypass is high-impact, and BeyondTrust RS/PRA has a track record of in-the-wild targeting. Rated CVSS 9.2, with low attack complexity making it the easier-to-exploit of the two BT26-03 flaws. 👉Upgrade to 26.2.1 or 25.3.3 (per BeyondTrust advisory BT26-03).

    Post summary

    BeyondTrust Remote Support suffers a critical pre‑auth authentication bypass (CVE‑2026‑40139) that allows unauthorized privileged access; the vendor recommends upgrading to version 26.2.1 or 25.3.3 to mitigate this CVSS‑9.2 flaw.

    00001119
    243 followersView on X
  • Cybersecurity News Alerts@secureblognews
    Patch

    🚨 CRITICAL ALERT: BeyondTrust Remote Support & PRA appliances hit with two pre-authentication bypass flaws (CVE-2026-40138 & CVE-2026-40139)! 🛑 Patch & fix guide 👇 https://cyberupdates365.com/beyondtrust-cve-2026-40138-40139-auth-bypass/ #CyberSecurity #InfoSec #Cybergate #latestnews

    Post summary

    BeyondTrust Remote Support and PRA appliances are affected by two pre-authentication bypass CVEs; the message provides a link to a patch and fix guide.

    0001089
    29 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-40139: BeyondTrust Remote Support Authentication Bypass - What It Means for Your Business and How to Respond https://hubs.li/Q04s5KSr0

    Post summary

    The text is a brief headline linking to an advisory on a BeyondTrust authentication bypass, providing no detailed information or actionable indicators.

    0000044
    32 followersView on X
  • Meridian Group@MeridianEU
    Patch

    #BeyondTrust patches four vulnerabilities in Remote Support and PRA: CVE-2026-40138 and CVE-2026-40139 (CVSS 9.2) enable unauthenticated auth bypass including privileged account access. CVE-2026-40140 enables pre-auth DoS; CVE-2026-40141 authenticated authz bypass. #patchrelease https://t.co/v1UUkcsaJ3

    Post summary

    BeyondTrust has released a patch for four high‑severity vulnerabilities (CVE‑2026‑40138, CVE‑2026‑40139, CVE‑2026‑40140, CVE‑2026‑40141) that include authentication bypasses and a denial‑of‑service flaw.

    0000057
    66 followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    🔐 BeyondTrust Remote Support & Privileged Remote Access hit with a critical pre-auth flaw (CVE-2026-40139, CVSS 9.2). Unauthenticated attackers can exploit the auth subsystem remotely. Patch immediately if you run either product. https://secalerts.co/vulnerability/CVE-2026-40139?utm_campaign=x https://t.co/PfXjlUDQtZ

    Post summary

    The post announces a critical pre-auth flaw in BeyondTrust Remote Support & Privileged Remote Access (CVE-2026-40139, CVSS 9.2) and urges immediate patching.

    00000107
    852 followersView on X
  • RedLegg@RedLegg
    Patch

    Security Bulletin: Critical BeyondTrust Vulnerabilities (CVE-2026-40138 & CVE-2026-40139) BeyondTrust has released fixes for two critical vulnerabilities affecting Remote Support and Privileged Remote Access. https://hubs.li/Q04nQ6Gx0

    Post summary

    BeyondTrust announced patches for CVE-2026-40138 and CVE-2026-40139, addressing critical remote support and privileged access vulnerabilities.

    0000077
    2.2K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2026-40139 in BeyondTrust Remote Support can bypass authentication and escalate to high-privilege accounts. The pre-auth vulnerability enables lateral movement across managed systems. Runtime segmentation helps contain post-compromise activity in privileged access infrastructure. #ZeroTrust #PrivilegedAccess 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/beyondtrust-remote-support-pra-auth-bypass-cve-2026-40138

    Post summary

    TRC analysis confirms attackers are actively exploiting CVE-2026-40139 to bypass authentication and enable lateral movement in BeyondTrust Remote Support.

    0000063
    1.9K followersView on X
  • TECHEPAGES@techepages
    Patch

    🚨 BeyondTrust has patched two critical pre-authentication flaws (CVE-2026-40138 and CVE-2026-40139, both CVSS 9.2) in Remote Support and Privileged Remote Access that could allow unauthenticated remote attackers to bypass access controls and gain elevated access to appliances. ⚠️ No in-the-wild exploitation has been reported, but prior RS/PRA flaws have been repeatedly exploited to deploy web shells and backdoors; prompt patching is strongly advised: 🔹 Remote Support: upgrade to RS 25.3.3 or above 🔹 Privileged Remote Access: upgrade to PRA 25.3.3 or above

    Post summary

    BeyondTrust has released patches for CVE-2026-40138 and CVE-2026-40139, urging upgrades to version 25.3.3, with no current evidence of in-the-wild exploitation.

    0000059
    19 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appbeyondtrustprivileged_remote_access---
Appbeyondtrustremote_support---

Explore more