BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Critical BeyondTrust bugs allow unauthenticated device takeover

BeyondTrust issues patches for four critical pre-authentication vulnerabilities in Remote Support and Privileged Remote Access

  • BeyondTrust disclosed four pre-authentication vulnerabilities in its Remote Support (RS) and Privileged Remote Access (PRA) products.
  • Two critical flaws (CVE-2026-40138 and CVE-2026-40139), each carrying a CVSS score of 9.2, could let unauthenticated attackers bypass access controls and gain elevated privileges.
  • Additional vulnerabilities include a denial-of-service flaw (CVE-2026-40140, CVSS 8.7) and an authenticated privilege escalation bug (CVE-2026-40141, CVSS 8.5).
  • BeyondTrust has released patched versions (RS 25.3.3 and PRA 25.3.3) and urges immediate updates, citing past exploitation of similar flaws.

On July 7, 2026, BeyondTrust released urgent security updates to patch four critical vulnerabilities in its Remote Support (RS) and Privileged Remote Access (PRA) products, warning that the most severe flaws could allow unauthenticated attackers to seize control of susceptible appliances. The two most critical issues, CVE-2026-40138 and CVE-2026-40139, both carry a CVSS score of 9.2 and stem from improper validation of authentication data, enabling a network-positioned attacker to bypass access controls and gain elevated privileges.

- Advertisement -

However, successful exploitation of these two critical flaws depends on a specific authentication configuration being enabled on the appliance. Meanwhile, the CVE-2026-40140 vulnerability (CVSS 8.7) is a pre-authentication denial-of-service issue caused by insufficient validation of client-supplied input, which could disrupt appliance availability. Additionally, CVE-2026-40141 (CVSS 8.5) is a privilege escalation flaw that, upon exploitation, is restricted to accounts with specific permissions.

BeyondTrust identified all four vulnerabilities internally during ongoing security assessments, with assistance from publicly available artificial intelligence models like Anthropic Claude Opus 4.8 and its own proprietary research tooling. The company stated, “The most severe vulnerabilities may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance under specific configurations.”

Consequently, BeyondTrust has addressed the issues in versions RS 25.3.3 and PRA 25.3.3 and above. Though no exploitation in the wild has been reported, the company emphasized that similar security flaws in RS and PRA products have been repeatedly exploited in the past to deploy web shells and backdoors, making it essential for users to apply fixes immediately.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

DogeOS opens public testnet for Dogecoin EVM apps on Sept 30

DogeOS launched a public testnet for its EVM-compatible application layer on Dogecoin on Sept....

Bitcoin ETFs 9th straight inflow day $66M beats Aug’s streak

U.S. spot Bitcoin ETFs recorded $66.19 million in net inflows on Sept. 29, marking...

Brazilian CSD tokenizes BTG Pactual fund shares on XRP Ledger

CSD BR is now live with tokenizing BTG Pactual fund share records on the...

AI infrastructure demand strong despite regulations: CoreWeave CEO

CoreWeave CEO Mike Intrator expects the economics of incremental AI infrastructure to keep improving...

Insiders made millions on .si domains before Trump SI order

Trump's executive order renaming AI to "Super Intelligence" may have enabled insider profits from...

Must Read

Cheapest Singapore VPS That Is Actually Worth Buying: 2026 Price Comparison

The cheapest Singapore VPS I found is $2.00 per month from Godlike Host. The cheapest from a provider I would put a production workload...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading