Skip to content
CC-4743

CC-4743

Digital.Nhs.Uk •[email protected] (NHS Digital) • February 9, 2026

A critical vulnerability could allow an unauthenticated attacker to perform remote code execution

A critical vulnerability could allow an unauthenticated attacker to perform remote code execution

The following platforms are known to be affected:

BeyondTrust Remote Support

BeyondTrust Privileged Remote Access

BeyondTrust has released a security advisory to address a critical vulnerability affecting Remote Support (RS) and Privileged Remote Access (PRA).

Affected organisations are encouraged to review the BeyondTrust Advisory bt26-02 and apply the relevant updates as soon as possible.

BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.

Last edited: 9 February 2026 2:36 pm