EXPOSURES › CVE-2026-1731
CVE-2026-1731
CRITICAL ⌖ ON CISA KEV · EXPLOITEDBeyondTrust Remote Support and Privileged Remote Access suffered an unpatched OS command injection flaw allowing unauthenticated remote attackers to execute arbitrary system commands.
The vulnerability in BeyondTrust's Remote Support and Privileged Remote Access products allowed unauthenticated remote attackers to execute arbitrary OS commands without user interaction, leading to system compromise, data exfiltration, and service disruption. This is a critical failure for DIB organizations relying on BeyondTrust for privileged access management, as it directly undermines the security of their remote support operations and exposes them to ransomware and data breaches. Organizations must immediately patch BeyondTrust products and review their supply chain risk for unpatched, actively exploited vulnerabilities.
Shame score — The flaw was actively exploited in the wild, linked to ransomware, and required no authentication or user interaction, representing a severe negligence in patching a known, critical vulnerability.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of the site user. Successful exploitation requires no authentication or user interaction and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption.
| PRODUCT | STATUS |
|---|---|
| Secure Remote Access BeyondTrust |
In Process |