PatchSiren cyber security CVE debrief
CVE-2026-1731 BeyondTrust CVE debrief
CVE-2026-1731 is a BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS command injection vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2026-02-13. CISA marks the issue as having known ransomware campaign use and sets a remediation due date of 2026-02-16. The supplied corpus does not include affected versions or a CVSS score, so defenders should rely on the vendor and official catalog guidance for exposure validation and mitigation status.
- Vendor
- BeyondTrust
- Product
- Remote Support (RS) and Privileged Remote Access (PRA)
- CVSS
- CRITICAL 9.9
- CISA KEV
- Listed
- Original CVE published
- 2026-02-13
- Original CVE updated
- 2026-02-13
- Advisory published
- 2026-02-13
- Advisory updated
- 2026-02-13
Who should care
Administrators and security teams responsible for BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA), especially if any deployments are internet accessible. Incident response and vulnerability management teams should also prioritize this issue because CISA lists it in KEV and flags known ransomware campaign use.
Technical summary
CISA classifies CVE-2026-1731 as an OS command injection affecting BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA). The KEV entry indicates known exploitation and notes known ransomware campaign use. No affected version range, exploit mechanics, or CVSS score are provided in the supplied corpus.
Defensive priority
Urgent. Treat this as a high-priority remediation item because it is in CISA KEV, has a short due date, and is associated with known ransomware campaign use.
Recommended defensive actions
- Apply vendor-recommended mitigations immediately.
- If mitigations are unavailable, discontinue use of the product where appropriate.
- Check all internet-accessible affected BeyondTrust systems for signs of compromise.
- Follow CISA BOD 22-01 guidance for cloud services where applicable.
- Verify mitigation or patch status and document exposure until remediation is complete.
Evidence notes
The supplied authoritative evidence is the CISA KEV record and its raw JSON feed entry, which identify BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) as the affected products, classify the issue as an OS command injection vulnerability, mark known ransomware campaign use as Known, and provide dateAdded 2026-02-13 with dueDate 2026-02-16. Official CVE and NVD links were supplied, but the corpus does not include additional vendor advisory text, affected versions, or CVSS data.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-1731 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-1731
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-1731 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-1731
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.