BeyondTrust released security updates for a critical pre-authentication remote code execution vulnerability in BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA). Tracked as CVE-2026-1731 (CVSS 9.9), the issue is described as an operating system command injection that can be triggered via specially crafted requests without authentication, allowing an attacker to execute OS commands in the context of the site user and potentially enabling unauthorized access, data exfiltration, and service disruption.
Affected versions include Remote Support 25.3.1 and earlier and Privileged Remote Access 24.3.4 and earlier. BeyondTrust provided fixes via RS Patch BT26-02-RS / RS 25.3.2+ and PRA Patch BT26-02-PRA / PRA 25.1.1+, and urged self-hosted customers to manually apply updates if not enrolled in automatic updates; older deployments (e.g., RS <21.3 or PRA <22.1) must first upgrade to a supported release line to apply the remediation. BeyondTrust’s SaaS instances were patched automatically (reported as completed on 2026-02-02), reducing exposure primarily to organizations operating self-managed installations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security released Alert AL26-003 warning that open-source reporting indicated CVE-2026-1731 was being exploited in the wild. It advised organizations to patch, review logs, restrict management interfaces, and remove internet exposure until remediation was complete.
Under Binding Operational Directive 22-01, CISA ordered Federal Civilian Executive Branch agencies to remediate CVE-2026-1731 by February 16, 2026. The directive reflected the short timeline imposed because the flaw was already being exploited in the wild.
CISA added CVE-2026-1731 to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation. The agency warned that the BeyondTrust flaw posed significant risk to federal networks and urged prioritized remediation.
Arctic Wolf reported a threat campaign exploiting CVE-2026-1731 to deploy SimpleHelp for persistence, perform Active Directory discovery, create privileged accounts, and move laterally with PsExec and Impacket SMB activity. The findings showed attackers were using the flaw for broader network takeover rather than simple opportunistic access.
watchTowr, GreyNoise, Defused Cyber, and other researchers reported active exploitation of CVE-2026-1731 against self-hosted BeyondTrust deployments. Security guidance shifted from urgent patching to assuming exposed unpatched systems may already be compromised.
Security researchers disclosed that attackers were abusing the /get_portal_info endpoint to obtain the x-ns-company identifier and then using a WebSocket channel to execute commands. Reports from GreyNoise, Defused Cyber, Rapid7, and others also described scanning activity, Nuclei-based checks, and multiple exploit tools in use.
By February 11, GreyNoise detected active probing for vulnerable BeyondTrust RS and PRA instances following the PoC release. The scanning was heavily concentrated from a single VPN-associated IP and often targeted non-standard ports, suggesting operators understood enterprise deployment patterns.
A proof-of-concept exploit for CVE-2026-1731 was published online, lowering the barrier to weaponization of the newly disclosed BeyondTrust flaw. Subsequent reporting linked the release to a rapid increase in attacker interest.
Government cyber authorities including Canada's Cyber Centre and Belgium's CCB published alerts directing administrators to review BeyondTrust's advisory and apply updates for CVE-2026-1731. These notices amplified the vendor's warning to public- and private-sector defenders.
Harsh Jaiswal and the Hacktron AI team were identified as the discoverers who privately disclosed CVE-2026-1731 to BeyondTrust. Their analysis also estimated roughly 11,000 internet-exposed instances, including about 8,500 on-prem systems potentially vulnerable if unpatched.
BeyondTrust published a security advisory for CVE-2026-1731, a critical pre-authentication OS command injection flaw in RS and PRA, and released patches and fixed versions for self-hosted deployments. The company warned that exploitation requires no authentication or user interaction and urged immediate patching or upgrade.
BeyondTrust deployed fixes for CVE-2026-1731 to its cloud-hosted Remote Support and Privileged Remote Access environments, automatically protecting SaaS customers. Self-hosted customers were not covered by this automatic remediation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
28 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcesecurityonline.info
Open sourcerapid7.com
Open sourceccb.belgium.be
Open sourcebleepingcomputer.com
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.