Critical severity9.8CISA KEVNVD Advisory· Published Feb 6, 2026· Updated Jun 17, 2026
CVE-2026-1731
CVE-2026-1731
Description
BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.
Affected products
5- cpe:2.3:a:beyondtrust:privileged_remote_access:*:*:*:*:*:*:*:*Range: <25.1
cpe:2.3:a:beyondtrust:remote_support:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:beyondtrust:remote_support:*:*:*:*:*:*:*:*range: <25.3.2
- (no CPE)
(expand)+ 1 more
- (no CPE)
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
4- www.beyondtrust.com/trust-center/security-advisories/bt26-02nvdVendor Advisory
- www.greynoise.io/blog/reconnaissance-beyondtrust-rce-cve-2026-1731nvdThird Party Advisory
- beyondtrustcorp.service-now.com/csmnvdPermissions Required
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
6- BeyondTrust warns of critical flaws in remote access softwareBleepingComputer · Jul 7, 2026
- BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRAThe Hacker News · Jul 7, 2026
- Exploits and vulnerabilities in Q1 2026Securelist · May 7, 2026
- ⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & MoreThe Hacker News · Apr 27, 2026
- Surge in Bomgar RMM Exploitation Demonstrates Supply Chain RiskDark Reading · Apr 21, 2026
- Risky Business #824 -- Microsoft's Secure Future is looking a bit wobblyRisky Business · Feb 11, 2026