U.S. health-sector authorities warned hospitals and clinics to urgently patch a critical vulnerability in BeyondTrust Remote Support and Privileged Remote Access that can provide attackers an initial foothold and enable unauthorized control of affected appliances inside enterprise networks. The flaw is tracked as CVE-2026-1731 and was highlighted to the healthcare and public health sector amid increased targeting of those organizations.
CISA added CVE-2026-1731 to its Known Exploited Vulnerabilities (KEV) catalog and set an accelerated remediation deadline for federal agencies, later updating the entry to warn that ransomware operators are actively exploiting the issue. Palo Alto Networks Unit 42 also reported observed in-the-wild exploitation, describing threat actors weaponizing the vulnerability to take control of appliances and expand access within victim environments, increasing risk to clinical networks if unpatched.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
HHS issued an alert to the healthcare and public health sector urging organizations to review and remediate the BeyondTrust vulnerability amid rising cyberattacks on the sector. The warning highlighted the risk that exploitation could provide attackers an initial foothold in clinical and corporate networks.
Palo Alto Networks Unit 42 reported that attackers were actively exploiting CVE-2026-1731 in BeyondTrust products. BeyondTrust warned successful exploitation could enable unauthorized access, data exfiltration, service disruption, and broader system compromise.
CISA later updated the KEV entry for CVE-2026-1731 to note that ransomware actors were exploiting the vulnerability. This marked an escalation from general active exploitation to ransomware-linked abuse.
CISA added CVE-2026-1731 to its Known Exploited Vulnerabilities catalog on February 13, 2026, indicating the flaw was being actively exploited. Federal agencies were given a three-day deadline to remediate the issue.
Health-ISAC issued a bulletin to the healthcare sector warning about the BeyondTrust vulnerability and its potential impact on provider organizations. The group emphasized the products are widely used for remote IT and clinical engineering support, raising the risk of enterprise-wide disruption and patient care impacts.
BeyondTrust released patches for a critical flaw in Remote Support and Privileged Remote Access on February 2, 2026. The company said updates were automatically deployed for instances using its update service and fully applied in SaaS environments.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.