Skip to content
BeyondTrust Issues Urgent Patch Advisory For Critical Remote Code Execution Flaw

BeyondTrust Issues Urgent Patch Advisory For Critical Remote Code Execution Flaw

Linkedin February 9, 2026

BeyondTrust has issued an urgent security advisory warning customers to immediately patch a newly disclosed critical vulnerability in two of its flagship enterprise products, Remote Support (RS) and Privileged Remote Access (PRA). The flaw, if left unpatched, could allow unauthenticated attackers to execute arbitrary code remotely, potentially leading to full system compromise.

The vulnerability, tracked as CVE-2026-1731 , was assigned a critical severity rating due to its low attack complexity, lack of authentication requirements, and the high level of access it could grant attackers. According to BeyondTrust, the issue stems from an operating system command injection weakness that can be exploited through specially crafted client requests.

Security researchers Harsh Jaiswal and the Hacktron AI research team discovered and responsibly disclosed the flaw.

In its advisory, BeyondTrust emphasized that exploitation does not require valid credentials or any user interaction, making the vulnerability particularly dangerous for internet-facing deployments.

The vulnerability affects:

BeyondTrust Remote Support versions 25.3.1 and earlier BeyondTrust Privileged Remote Access versions 24.3.4 and earlier

Both products are widely deployed in enterprise and government environments to facilitate remote troubleshooting and controlled access to sensitive systems.

In an independent analysis published Friday, the Hacktron AI team warned that the exposure footprint remains significant.

While BeyondTrust confirmed that all of its cloud-hosted RS and PRA environments were secured by February 2 , the company cautioned that on-premises customers must manually apply updates unless automatic patching is enabled.

BeyondTrust is urging customers to upgrade to:

Remote Support 25.3.2 or later Privileged Remote Access 25.1.1 or later

Following publication of early reports, BeyondTrust told reporters that it has no evidence of active exploitation of CVE-2026-1731 in the wild as of this week. However, public disclosure of critical, pre-authentication flaws often leads to rapid weaponization by threat actors.

Historically, vulnerabilities affecting remote access and privileged identity systems are among the fastest to be exploited, particularly when proof-of-concept code becomes available.

Although BeyondTrust says this vulnerability has not yet been abused, the company’s software has previously been targeted in high-profile attacks.

In late 2024, attackers leveraged two previously unknown RS/PRA zero-day vulnerabilities— CVE-2024-12356 and CVE-2024-12686 —to breach BeyondTrust’s infrastructure and steal a valid API key. That access was later used to compromise 17 Remote Support SaaS customer environments .

Less than a month later, the U.S. Department of the Treasury disclosed that its network had been breached through a compromised BeyondTrust instance. U.S. officials later attributed the attack to Silk Typhoon , a state-aligned threat actor believed to be operating on behalf of China.

Investigators said the attackers accessed unclassified but sensitive Treasury data related to potential sanctions activity. Additional targets reportedly included:

The Committee on Foreign Investment in the United States (CFIUS) The Office of Foreign Assets Control (OFAC)

In response to those incidents, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2024-12356 to its Known Exploited Vulnerabilities Catalog and ordered U.S. federal agencies to remediate affected systems within days.

BeyondTrust’s tools sit at a uniquely sensitive position in enterprise environments. Remote Support enables technicians to access endpoints across corporate networks, while Privileged Remote Access functions as a gateway controlling administrative connections to servers, databases, and cloud resources.

Any unauthenticated RCE in a privileged access platform is effectively a skeleton key and It collapses the trust boundary those tools are designed to enforce.

Security teams are advised to:

Apply vendor patches immediately Restrict external access to RS/PRA interfaces where possible Review logs for unusual client requests or command execution Monitor for indicators of compromise following patch deployment

We also recommend treating any unpatched internet-facing privileged access system as a potential breach risk until proven otherwise.

As attackers continue to prioritize identity infrastructure, CVE-2026-1731 serves as a reminder that tools designed to protect access can quickly become high-impact attack vectors when vulnerabilities emerge.

Read the complete BeyondTrust Advisory HERE

BeyondTrust provides identity and access security services to more than 20,000 organizations across over 100 countries, including approximately 75% of Fortune 100 companies. Its products are widely used in regulated industries such as finance, healthcare, energy, and government—sectors frequently targeted by sophisticated threat actors.

Wednesday, February 18 at 12 PM ET for Securely Yours: When IAM Meets the CISO, a Valentine's-themed webinar exploring this essential security duo.

💜 What makes this partnership work (spoiler: trust, not romance)

💜 How alignment strengthens both teams and the organization

💜 Why organizations perform best when these two move as one

This session is perfect for anyone who wants to protect their org without losing sleep, or sanity.