BeyondTrust disclosed and fixed CVE-2026-1731, a critical unauthenticated remote code execution flaw affecting Remote Support 25.3.1 and earlier and Privileged Remote Access 24.3.4 and earlier. The vulnerability allows a remote attacker to send crafted client requests and execute system commands on the target appliance as the site user, creating a path to full system compromise, data theft, and service disruption. CSIRT.SK reported the issue carries a CVSS score of 9.9.
BeyondTrust said cloud instances were updated automatically, while organizations running on-premises deployments were told to upgrade to Remote Support 25.3.2 and Privileged Remote Access 25.1.1, or apply the vendor patches BT26-02-RS and BT26-02-PRA. The advisory identifies the flaw as a high-priority risk for enterprises using BeyondTrust remote access and support platforms because exploitation requires no authentication and can result in command execution on exposed systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK reported the critical BeyondTrust flaw and advised administrators of on-premises instances to upgrade to Remote Support 25.3.2 and Privileged Remote Access 25.1.1 or apply patches BT26-02-RS and BT26-02-PRA. The report also noted that BeyondTrust had already automatically updated cloud instances.
BeyondTrust disclosed and fixed the critical vulnerability CVE-2026-1731 affecting Remote Support and Privileged Remote Access. The flaw allows an unauthenticated remote attacker to send crafted client requests and execute system commands as the site user.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.