A critical vulnerability could allow an unauthenticated attacker to perform remote code execution
A critical vulnerability could allow an unauthenticated attacker to perform remote code execution
The following platforms are known to be affected:
BeyondTrust Privileged Remote Access
BeyondTrust has released a security advisory to address a critical vulnerability affecting Remote Support (RS) and Privileged Remote Access (PRA).
Affected organisations are encouraged to review the BeyondTrust Advisory bt26-02 and apply the relevant updates as soon as possible.
BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.
Last edited: 9 February 2026 2:36 pm
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
