FAIL › dossier
BeyondTrust
COMPANY FEDRAMP MARKETFedRAMP provider · · dossier confidence 20%
BeyondTrust has experienced a series of critical security failures, indicating a need for rigorous security reviews and a commitment to timely patching of vulnerabilities.
PROFILE
CategoryCybersecurityWhat they doBeyondTrust provides privileged access management solutions that allow organizations to secure and manage remote access to systems and applications.
Websitehttps://www.beyondtrust.com ↗
SECURITY POSTURE
BeyondTrust has faced multiple critical vulnerabilities that have been exploited by attackers, indicating a potential lack of robust security practices and post-purchase integration.
Notable failures
- CVE-2026-1731: Critical (RCE) vulnerability in BeyondTrust Remote Support and Privileged Remote Access.
- CVE-2025-12686: High (RCE) vulnerability in BeyondTrust Privileged Remote Access and Remote Support.
- CVE-2024-12356: High (RCE) vulnerability in BeyondTrust Privileged Remote Access and Remote Support.
- CVE-2026-40141: Critical (RCE) vulnerability in a web application component of BeyondTrust Remote Support and Privileged Remote Access.
- CVE-2026-40139: Critical (pre-authentication RCE) vulnerability in the authentication subsystem of BeyondTrust Remote Support.
Patterns: Repeated unpatched edge-device RCE vulnerabilities.; High-severity vulnerabilities in web application components.; Pre-authentication vulnerabilities in authentication subsystems.
FAILURE HISTORY · 5
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-02-13 | CVE-2026-1731 | critical | BeyondTrust Remote Support and Privileged Remote Access suffered an unpatched OS command injection flaw allowing unauthenticated remote attackers to execute arbitrary system commands. |
| 2024-12-19 | CVE-2024-12356 | high | BeyondTrust PRA/RS allows unauthenticated attackers to execute commands as site users via command injection. |
| 2025-01-13 | CVE-2024-12686 | high | BeyondTrust PRA/RS allows attackers with admin access to upload malware and execute OS commands via command injection. |
| 2026-07-06 | CVE-2026-40141 | critical | A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated attacker with limited pr |
| 2026-07-06 | CVE-2026-40139 | critical | A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, i |
FEDRAMP CATALOG PRODUCTS · 1
| PRODUCT | STATUS | IMPACT |
|---|---|---|
| Secure Remote Access | In Process | Moderate |
DOSSIER SOURCES
- Credo Technology Group Holding (CRDO) Company Profile & Description · stockanalysis.com
- BeyondTrust Status. Check if BeyondTrust is down or ... - StatusGator · statusgator.com
- Vulnerability - cert-in.org.in · www.cert-in.org.in
- Vulnerability Report Archives • Page 4 of 90 • Daily CyberSecurity · securityonline.info
- Your BeyondTrust Software Has Critical Flaws — Here's What You Need To Do · www.af1.in
- The New Insider Has No Pulse: Securing Privilege When the Actor Is an ... · The Hacker News
- Vulnerability - cert-in.org.in · www.cert-in.org.in
Open questions: How has BeyondTrust addressed these vulnerabilities? · What improvements has the company made to its security posture?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-24 03:46:12.061642+00:00