BeyondTrust Remote Support is being actively exploited via CVE-2026-1731, a critical pre-authentication OS command injection / RCE flaw (CVSS 9.9) in the thin-scc-wrapper component exposed to the internet via WebSocket. Reporting indicates attackers can execute system commands without logging in, enabling rapid progression from initial access to full compromise, including reconnaissance, account creation, webshell deployment, C2 activity, lateral movement, and data theft. Victimology described to date spans multiple sectors—financial services, healthcare, legal services, higher education, and technology/retail—across the U.S., France, Germany, Australia, and Canada, with telemetry indicating 10,600+ exposed instances potentially at risk.
Threat activity observed in exploitation includes deployment of two prominent remote-access backdoors: VShell (noted for stealthy, service-like behavior and fileless/memory execution on Linux) and SparkRAT (an open-source Go-based RAT previously seen in campaigns linked to DragonSpark). Due to confirmed exploitation, CISA added CVE-2026-1731 to the KEV Catalog (Feb. 13, 2026), signaling urgent patching/mitigation prioritization. Separate reporting in the same period covered unrelated critical issues in GNU Inetutils telnetd (CVE-2026-24061) and an exploitation surge affecting Ivanti products (CVE-2025-0282/CVE-2025-0283), but those are distinct from the BeyondTrust activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
BeyondTrust stated that exploitation of CVE-2026-1731 was first detected on 2026-01-31 and was largely limited to unpatched, internet-facing, self-hosted appliances before 2026-02-09. This disclosure clarified the campaign's start and early scope.
By 2026-02-20, CISA had updated its KEV entry for CVE-2026-1731 to state that ransomware actors were exploiting the vulnerability. This marked an escalation from general active exploitation to confirmed use in ransomware campaigns.
On 2026-02-20, reporting said the U.S. Department of Health and Human Services issued an alert urging healthcare and public health organizations to review and address CVE-2026-1731. The warning highlighted the risk that the flaw could give attackers an initial foothold in hospital and clinic networks.
By 2026-02-19, Palo Alto Networks Unit 42 reported active in-the-wild exploitation of CVE-2026-1731 affecting multiple industries and countries. Observed post-exploitation activity included reconnaissance, web shell deployment, persistence, lateral movement, and use of VShell and SparkRAT.
On 2026-02-13, CISA added CVE-2026-1731 to its Known Exploited Vulnerabilities catalog, requiring U.S. federal agencies to remediate it on an urgent timeline. Other organizations were also urged to take immediate action.
A public proof-of-concept for CVE-2026-1731 was released on 2026-02-10. Reporting says exploitation activity accelerated after the PoC became available.
On 2026-02-06, BeyondTrust disclosed the critical pre-authentication command-injection flaw CVE-2026-1731 affecting Remote Support and Privileged Remote Access, and issued fixes. The company advised customers to upgrade to patched versions, including Remote Support 25.3.2 and Privileged Remote Access 25.1.1.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcesecurityaffairs.com
Open sourcesecpod.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcedatabreaches.net
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.