VulnerabilityBleeping Computer
9.9 — CRITICAL
BeyondTrust warns of critical flaws in remote access software
BeyondTrust warned customers to patch two critical security flaws in its Remote Support (RS) and Privileged Remote Access (PRA) software that could allow attackers to bypass authentication. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
BeyondTrust has identified two critical security flaws in its Remote Support and Privileged Remote Access software, which could allow attackers to bypass authentication and gain unauthorized access to appliances. The vulnerabilities were patched on April 21, 2026, but users are advised to apply the patch as soon as possible.
⚙️Technical Details
CVEs
CVE-2026-40138CVE-2026-40139CVE-2026-40140CVE-2026-40141CVE-2026-1731
Affected Systems
Beyondtrust Privileged Remote AccessBeyondtrust Remote Support
Attack Vectors
NETWORK
💥Impact Assessment
Severity: CRITICAL
Who Is at Risk
Users of BeyondTrust Remote Support and Privileged Remote Access software, including U.S. government agencies
🛡️Recommended Actions
1Apply the April security rollup patch for affected versions
2Upgrade to RS 25.3.3 & above or PRA 25.3.3 & above
3Disable specific authentication configurations that are not necessary
📦Affected Products
Beyondtrust Privileged Remote AccessBeyondtrust Remote Support
🔐NVD Verified DataVERIFIED
CVE-2026-40138 ↗CVSS 8.1 — HIGH
Attack Vector
NETWORK
Complexity
HIGH
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-287
Affected Products (CPE)
Beyondtrust Privileged Remote AccessBeyondtrust Remote Support
CVE-2026-40139 ↗CVSS 9.8 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-287
Affected Products (CPE)
Beyondtrust Privileged Remote AccessBeyondtrust Remote Support
CVE-2026-40140 ↗CVSS 7.5 — HIGH
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HWeaknesses
CWE-400
Affected Products (CPE)
Beyondtrust Privileged Remote AccessBeyondtrust Remote Support
CVE-2026-40141 ↗CVSS 9.9 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HWeaknesses
CWE-943
Affected Products (CPE)
Beyondtrust Privileged Remote AccessBeyondtrust Remote Support
CVE-2026-1731 ↗CVSS 9.8 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-78
Affected Products (CPE)
Beyondtrust Privileged Remote AccessBeyondtrust Remote Support
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
