Cyber Security News

BeyondTrust Remote Access Products 0-Day Vulnerability Allows Remote Code Execution

BeyondTrust has disclosed a critical pre-authentication remote code execution vulnerability affecting its Remote Support (RS) and Privileged Remote Access (PRA) platforms, potentially exposing thousands of organizations to system compromise.

The flaw, tracked as CVE-2026-1731 and classified under CWE-78 (OS Command Injection), enables attackers to execute arbitrary operating system commands without requiring authentication or user interaction.

The security flaw allows unauthenticated remote attackers to send specially crafted requests to vulnerable BeyondTrust systems, triggering command execution in the context of the site user.

This represents a severe threat as it requires no prior access credentials or social engineering tactics, making it an attractive target for malicious actors seeking to compromise enterprise remote access infrastructure.

Successful exploitation could lead to complete system compromise, enabling attackers to gain unauthorized access to sensitive data, exfiltrate confidential information, disrupt critical services, and potentially pivot to other systems within the network.

Given that BeyondTrust products are commonly used for privileged access management and remote support across enterprise environments, the vulnerability’s impact extends beyond individual systems to entire organizational infrastructures.

Remote Support versions 25.3.1 and earlier are vulnerable to this exploit. For Privileged Remote Access, versions 24.3.4 and prior contain the security flaw. Organizations running these versions should take immediate action to protect their systems.

Immediate Action Required

BeyondTrust has responded swiftly to the threat. All Remote Support SaaS and Privileged Remote Access SaaS customers received automatic patches on February 2, 2026, fully remediating the vulnerability.

However, self-hosted customers must take manual action. Organizations using self-hosted deployments should immediately apply patch BT26-02-RS for Remote Support or patch BT26-02-PRA for Privileged Remote Access through their /appliance interface, provided automatic updates are not enabled.

Customers running Remote Support versions older than 21.3 or Privileged Remote Access versions older than 22.1 must first upgrade to a supported version before applying the security patch. Remote Support customers should upgrade to version 25.3.2 or later for complete protection.

The vulnerability was discovered by Harsh Jaiswal and the Hacktron AI team, who employed AI-enabled variant analysis techniques to identify the flaw.

BeyondTrust commended their responsible disclosure process, which enabled the company to investigate, develop patches, and notify customers before public exploitation could occur.

Organizations using affected BeyondTrust products should prioritize patching immediately to prevent potential exploitation of this critical vulnerability.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago