A critical pre-authentication remote code execution flaw in BeyondTrust Remote Support and some older versions of Privileged Remote Access, tracked as CVE-2026-1731, has been actively exploited against internet-facing systems. The bug is described as an unauthenticated operating system command injection vulnerability that lets attackers execute arbitrary commands on affected servers. BeyondTrust patched its SaaS customers on February 2 and urged self-hosted customers to apply fixes, while CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and public exploit code later appeared on GitHub.
Incident responders and threat researchers reported a rise in post-exploitation activity across multiple BeyondTrust customers in sectors including financial services, technology, higher education, legal services, and healthcare. Palo Alto Networks Unit 42 observed attackers deploying SparkRAT and vShell backdoors, using remote management and tunneling tools for reconnaissance and persistence, and in some cases conducting environment enumeration and suspected data theft. Censys and other researchers also warned that exposed BeyondTrust instances were reachable from the internet, underscoring the risk of rapid compromise where patches had not been applied.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
A GitHub repository publishing exploit code for CVE-2026-1731 became publicly available, lowering the barrier to exploitation. The repository was published on 2026-02-22.
Researchers reported attackers using SparkRAT and vShell backdoors, along with remote management and tunneling tools, for reconnaissance, persistence, and follow-on activity after exploiting CVE-2026-1731. Additional reporting also noted active reconnaissance, possible initial access broker involvement, environment enumeration, and data theft.
Palo Alto Networks Unit 42 reported confirmed targeting of multiple BeyondTrust customers across sectors including financial services, technology, higher education, legal services, and healthcare. About a dozen cases showed confirmed compromise or high-confidence unauthorized intrusion tied to exploitation of CVE-2026-1731.
CISA added CVE-2026-1731 to its Known Exploited Vulnerabilities catalog after exploitation activity was observed in the wild. This marked the flaw as actively exploited and elevated urgency for remediation.
Public advisories described CVE-2026-1731 as a critical flaw enabling arbitrary command execution on vulnerable BeyondTrust Remote Support servers, with impact extending to some older Privileged Remote Access versions. Censys published an advisory referencing the issue on 2026-02-10.
BeyondTrust disclosed CVE-2026-1731, a pre-authentication/unauthenticated command injection flaw affecting Remote Support and some older Privileged Remote Access versions. The company patched its SaaS customers on 2026-02-02 and advised self-hosted customers to apply available fixes manually.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcecybersecuritydive.com
Open sourcecensys.com
Open sourcecybernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.