PatchSiren

BeyondTrust CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited BeyondTrust CVE published 2026-02-13

CVE-2026-1731

CVE-2026-1731 is a BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS command injection vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2026-02-13. CISA marks the issue as having known ransomware campaign use and sets a remediation due date of 2026-02-16. The supplied corpus does not include affected versions or a CVSS score, so defenders should rely on t [truncated]

Known exploited BeyondTrust CVE published 2025-01-13

CVE-2024-12686

CVE-2024-12686 is an OS command injection vulnerability affecting BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS). CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on 2025-01-13, which means defenders should treat it as an urgent remediation item rather than a routine patch cycle issue. The supplied corpus does not include affected versions or deeper technical detail, [truncated]

Known exploited BeyondTrust CVE published 2024-12-19

CVE-2024-12356

CVE-2024-12356 is a BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) command injection vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2024-12-19. The KEV listing means this issue is treated as actively exploited or sufficiently validated for urgent defensive action. The supplied corpus does not include affected versions, CVSS scoring, or detailed impact a [truncated]