FeedVulnerabilityBeyondTrust warns of critical flaws in remote access softwar...
VulnerabilityBleeping Computer
9.9CRITICAL

BeyondTrust warns of critical flaws in remote access software

📅 7 July 2026 at 08:12 UTC📰 Bleeping ComputerView original source ↗
BeyondTrust warns of critical flaws in remote access software

BeyondTrust warned customers to patch two critical security flaws in its Remote Support (RS) and Privileged Remote Access (PRA) software that could allow attackers to bypass authentication. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

BeyondTrust has identified two critical security flaws in its Remote Support and Privileged Remote Access software, which could allow attackers to bypass authentication and gain unauthorized access to appliances. The vulnerabilities were patched on April 21, 2026, but users are advised to apply the patch as soon as possible.

⚙️Technical Details
CVEs
CVE-2026-40138CVE-2026-40139CVE-2026-40140CVE-2026-40141CVE-2026-1731
Affected Systems
Beyondtrust Privileged Remote AccessBeyondtrust Remote Support
Attack Vectors
NETWORK
💥Impact Assessment
Severity: CRITICAL
Who Is at Risk
Users of BeyondTrust Remote Support and Privileged Remote Access software, including U.S. government agencies
🛡️Recommended Actions
1Apply the April security rollup patch for affected versions
2Upgrade to RS 25.3.3 & above or PRA 25.3.3 & above
3Disable specific authentication configurations that are not necessary
📦Affected Products
Beyondtrust Privileged Remote AccessBeyondtrust Remote Support
🔐NVD Verified DataVERIFIED
CVE-2026-40138CVSS 8.1HIGH
Attack Vector
NETWORK
Complexity
HIGH
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-287
Affected Products (CPE)
Beyondtrust Privileged Remote AccessBeyondtrust Remote Support
CVE-2026-40139CVSS 9.8CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-287
Affected Products (CPE)
Beyondtrust Privileged Remote AccessBeyondtrust Remote Support
CVE-2026-40140CVSS 7.5HIGH
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-400
Affected Products (CPE)
Beyondtrust Privileged Remote AccessBeyondtrust Remote Support
CVE-2026-40141CVSS 9.9CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-943
Affected Products (CPE)
Beyondtrust Privileged Remote AccessBeyondtrust Remote Support
CVE-2026-1731CVSS 9.8CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-78
Affected Products (CPE)
Beyondtrust Privileged Remote AccessBeyondtrust Remote Support

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer
← Back to feed