A high-severity vulnerability exists in BeyondTrust Remote Support and Privileged Remote Access related to input parameter processing. Insufficient validation may allow an authenticated attacker with limited privileges to access unintended resources or data. Exploitation is restricted to accounts with specific permissions. This issue has a CVSS score of 8.5 and is classified as HIGH. Administrators and us [truncated]
CVE-2026-40140 is a high-severity pre-authentication vulnerability in BeyondTrust Remote Support and Privileged Remote Access. Insufficient validation of client-supplied input may allow an unauthenticated remote attacker to trigger a denial-of-service condition affecting appliance availability. This vulnerability exists in the network communication subsystem. Organizations should prioritize patching to pr [truncated]
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled. This vu [truncated]
CVE-2026-40138 is a critical pre-authentication vulnerability in BeyondTrust Remote Support and Privileged Remote Access. The vulnerability exists due to improper validation of authentication data, allowing a network-positioned attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication confi [truncated]
Known exploitedBeyondTrustCVE published 2026-02-13
CVE-2026-1731 is a BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS command injection vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2026-02-13. CISA marks the issue as having known ransomware campaign use and sets a remediation due date of 2026-02-16. The supplied corpus does not include affected versions or a CVSS score, so defenders should rely on t [truncated]
Known exploitedBeyondTrustCVE published 2025-01-13
CVE-2024-12686 is an OS command injection vulnerability affecting BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS). CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on 2025-01-13, which means defenders should treat it as an urgent remediation item rather than a routine patch cycle issue. The supplied corpus does not include affected versions or deeper technical detail, [truncated]
Known exploitedBeyondTrustCVE published 2024-12-19
CVE-2024-12356 is a BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) command injection vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2024-12-19. The KEV listing means this issue is treated as actively exploited or sufficiently validated for urgent defensive action. The supplied corpus does not include affected versions, CVSS scoring, or detailed impact a [truncated]