Tuesday, September 8, 2026

BeyondTrust Remote Access Products Hit by 0-Day RCE Vulnerability

BeyondTrust has issued an urgent security advisory regarding a critical zero-day vulnerability affecting its popular remote access solutions.

The flaw, tracked as CVE-2026-1731, carries a near-maximum severity score of 9.9 out of 10 on the CVSSv4 scale.

It poses a significant risk to organizations using self-hosted versions of BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA).

The Vulnerability: CVE-2026-1731

The vulnerability is classified as a “pre-authentication remote code execution” (RCE) issue. This is considered one of the most dangerous types of security flaws.

In simple terms, “pre-authentication” means an attacker does not need a username, password, or any valid credentials to exploit the system.

“Remote code execution” means the attacker can run commands on the victim’s server from anywhere on the internet.

According to the advisory, the flaw stems from an OS Command Injection issue (CWE-78).

By sending a specially crafted request to a vulnerable appliance, an unauthenticated attacker can execute operating system commands with the privileges of the “site user.”

Successful exploitation could lead to total system compromise, unauthorized data theft, or service disruption without any interaction from a legitimate user.

The vulnerability affects the following products:

  • Remote Support (RS): Version 25.3.1 and prior.
  • Privileged Remote Access (PRA): Version 24.3.4 and prior.

The urgency of the response depends on how your organization deploys BeyondTrust software:

1. Cloud/SaaS Customers: You are already protected. BeyondTrust applied a patch to all SaaS instances on February 2, 2026. No further action is required for cloud-hosted environments.

2. Self-Hosted/On-Premise Customers: You are at risk and must take action immediately. Administrators should log in to their appliance interface and check for updates.

  • Remote Support users must upgrade to version 25.3.2 or later (Patch BT26-02-RS).
  • Privileged Remote Access users must upgrade to version 25.1.1 or later (Patch BT26-02-PRA).

This vulnerability was responsibly disclosed by Harsh Jaiswal and the Hacktron AI team.

The discovery is notable because it utilized a novel approach involving AI-enabled variant analysis, highlighting the growing role of artificial intelligence in both defending and auditing cybersecurity infrastructure.

Security teams are advised to review their logs for suspicious activity and prioritize patching immediately, given the critical nature of the flaw and the potential for active exploitation.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Claude Mythos Executes End-to-End Intrusion From Initial Access to Full Domain Compromise

Anthropic’s Claude Mythos Preview has demonstrated the ability to...

WhatsApp Testing Guest Calls for People Without a WhatsApp Account

WhatsApp is developing a guest-call feature that would let...

The 12 Best Antivirus (Endpoint Protection) Software for Business, Compared and Priced

Best value overall: Microsoft Defender for Endpoint — if...

The 12 Best Managed Firewall Services, Compared and Priced

Best value overall: Fortinet. Delivered directly and through the...

Related Articles

Recent News