Skip to content
COOEY

EXPOSURES › CVE-2026-1731

CVE-2026-1731

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-02-13 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-1731 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

BeyondTrust Remote Support and Privileged Remote Access suffered an unpatched OS command injection flaw allowing unauthenticated remote attackers to execute arbitrary system commands.

The vulnerability in BeyondTrust's Remote Support and Privileged Remote Access products allowed unauthenticated remote attackers to execute arbitrary OS commands without user interaction, leading to system compromise, data exfiltration, and service disruption. This is a critical failure for DIB organizations relying on BeyondTrust for privileged access management, as it directly undermines the security of their remote support operations and exposes them to ransomware and data breaches. Organizations must immediately patch BeyondTrust products and review their supply chain risk for unpatched, actively exploited vulnerabilities.

Shame score — The flaw was actively exploited in the wild, linked to ransomware, and required no authentication or user interaction, representing a severe negligence in patching a known, critical vulnerability.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of the site user. Successful exploitation requires no authentication or user interaction and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption.

AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Secure Remote Access
BeyondTrust
In Process