Critical BeyondTrust Flaw Allows RCE

Critical BeyondTrust flaw allows unauthenticated system takeover; patch immediately.

  • BeyondTrust has patched a critical remote code execution flaw (CVE-2026-1731) in its Remote Support and Privileged Remote Access software.
  • The vulnerability, with a CVSS score of 9.9, allows unauthenticated attackers to execute operating system commands on affected systems.
  • Security researcher Harsh Jaiswal noted the flaw was found via AI analysis, with about 11,000 instances, including 8,500 on-prem deployments, exposed online.
  • Users must manually apply patches if not on automatic updates, with some older versions requiring a full upgrade for protection.

On February 6, 2026, BeyondTrust issued a critical security advisory, warning of a severe vulnerability in its widely used Remote Support and Privileged Remote Access products. This flaw, if exploited, could allow attackers to remotely execute commands on systems without any authentication required.

- Advertisement -

The vulnerability, tracked as CVE-2026-1731, is an operating system command injection flaw rated 9.9 on the CVSS scale. BeyondTrust said in its advisory that sending specially crafted requests could let an attacker run commands as the site user.

Consequently, successful exploitation may lead to unauthorized access, data theft, and major service disruptions. The issue impacts Remote Support versions 25.3.1 and prior, as well as Privileged Remote Access versions 24.3.4 and prior.

Patches are available in Remote Support version 25.3.2 and Privileged Remote Access 25.1.1. Meanwhile, the company is urging all self-hosted customers who do not receive automatic updates to apply the fixes manually.

Security researcher Harsh Jaiswal, co-founder of Hacktron AI, said the bug was discovered on January 31, 2026, through AI-enabled analysis. He added that it found about 11,000 instances exposed to the internet, with roughly 8,500 being on-prem deployments that remain vulnerable without the patch.

- Advertisement -

Given that past flaws in these BeyondTrust products have been actively exploited, applying the update is urgently recommended for optimal protection.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Bitcoin Options Hedging Amplifies Plunge to $60K

Bitcoin's recent decline from $77,000 to near $60,000 in early February was accelerated by...

India’s US-EU Trade Deals Shift Tensions With China in BRICS

India signs major trade deals with the U.S. and EU in early February 2026,...

Bitcoin Rally Fades as Investor Warns of Regulations

Investor Mark Yusko challenges the view that the Trump administration is broadly pro-crypto, warning...

FDIC pays Coinbase $188k, settles FOIA lawsuit

The FDIC will pay $188,440 in legal fees and overhaul its FOIA policies to...

Goldman Sachs $250 Nvidia Target Sees 35% Upside

Goldman Sachs has raised its NVIDIA stock price target to $250, implying roughly 35%...

Must Read

Top 7 BEST Crypto Trading Bots for Beginners

QUICK NAVIGATIONQuick Look: Top 3 Best Crypto Trading BotsWhat Exactly is a Crypto Trading Bot?How I Chose These Trading BotsTop 7 Crypto Trading Bots...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!