BeyondTrust disclosed multiple vulnerabilities affecting Remote Support and Privileged Remote Access appliances, including two critical pre-authentication authentication-bypass flaws tracked as CVE-2026-40138 and CVE-2026-40139. Both issues carry CVSS 9.2 ratings and can allow remote attackers to gain unauthorized access, including access to elevated-privilege accounts, when a specific authentication configuration is enabled. A separate pre-authentication flaw, CVE-2026-40140, was rated CVSS 8.7 and can be exploited remotely to cause a denial-of-service condition in the network communication subsystem.
BeyondTrust also addressed CVE-2026-40141, a CVSS 8.5 vulnerability in a web application component that could let an authenticated low-privilege user access resources or data outside their intended authorization scope. The affected products are Remote Support 25.3.2 and earlier and Privileged Remote Access 25.3.2 and earlier. The Canadian Centre for Cyber Security urged administrators to review BeyondTrust’s advisory, apply vendor updates, disable the affected authentication configuration where possible, and review access controls and permissions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-40141 was disclosed as a high-severity vulnerability in a web application component of BeyondTrust Remote Support and Privileged Remote Access. An authenticated attacker with limited privileges could exploit insufficient input validation to access unintended resources or data outside their authorization scope.
CVE-2026-40140 was disclosed as a high-severity pre-authentication vulnerability in BeyondTrust Remote Support and Privileged Remote Access. The network communication flaw can be exploited remotely by an unauthenticated attacker to trigger a denial-of-service condition affecting appliance availability.
CVE-2026-40139 was disclosed as a critical pre-authentication vulnerability in BeyondTrust Remote Support and Privileged Remote Access. Improper processing of authentication requests can let an unauthenticated remote attacker bypass access controls and gain unauthorized access, including elevated-privilege accounts, under a specific authentication configuration.
CVE-2026-40138 was disclosed as a critical pre-authentication vulnerability in BeyondTrust Remote Support and Privileged Remote Access. The flaw allows a network-positioned attacker to bypass access controls and gain unauthorized access, including elevated-privilege accounts, when a specific authentication configuration is enabled.
BeyondTrust published a security advisory addressing vulnerabilities affecting Remote Support version 25.3.2 and prior and Privileged Remote Access version 25.3.2 and prior. The advisory urged customers to review the notice and apply necessary updates.
BeyondTrust said its cloud-hosted Remote Support and Privileged Remote Access customers were automatically patched for the vulnerabilities. The company contrasted this with self-hosted customers, who were told to apply the April 2026 security rollup or upgrade to version 25.3.3 or later.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
15 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcethreataft.com
Open sourcehkcert.org
Open sourcesocradar.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.