Critical pre-auth RCE in BeyondTrust remote-support tools prompts urgent patch

TL;DR
BeyondTrust warns of CVE-2026-1731, a pre-auth remote code execution flaw in Remote Support (RS) 25.3.1 and Privileged Remote Access (PRA) 24.3.4 and earlier, allowing unauthenticated attackers to run OS commands; patches are available by upgrading to RS 25.3.2+ and PRA 25.1.1+ (or enabling automatic updates). Cloud systems have been secured; about 11,000 instances are exposed online, with roughly 8,500 on-premises potentially vulnerable if not patched; no active exploitation is reported yet.
Topics:businesstechnology#enterprise-security#patch-management#remote-code-execution#security#technology#vulnerability
- BeyondTrust warns of critical RCE flaw in remote support software BleepingComputer
- BeyondTrust Fixes Critical Pre-Auth RCE Vulnerability in Remote Support and PRA The Hacker News
- CVE-2026-1731 Arctic Wolf
- BeyondTrust's Pre-Authentication RCE Flaw Exposes the Fragile Underbelly of Privileged Access Management WebProNews
- BeyondTrust Remote Support has a critical vulnerability Techzine Global
Want the full story? Read the original reporting
Read on BleepingComputer