CVE detail
CVE-2026-1731
BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 1
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
26 source links · newest first
task. Figure 1. Autonomous attack flow observed in Hermes Agent session (May 5, 2026). Phase 1: Langflow Exploitation (CVE-2026-33017) DeepSeek identified a Langflow vulnerability ( CVE-2026-33017 , CVSS 9.8) and autonomously attempted exploitation through the following steps: Downloading the public PoC exploit from GitHub Enumerating 84 Langflow inst
vendorunit42.paloaltonetworks.comJul 30, 2026, 10:00 AMChina-based actor Storm-1175 runs fast ransomware attacks, exploiting new flaws to breach systems and quickly deploy Medusa ransomware. China-based actor Storm-1175 carries out fast, financially driven ransomware attacks by exploiting newly disclosed vulnerabilities before organizations patch them. The group targets exposed systems and quickly moves from initial access to data theft and Medusa ransomware deployment, […]
newssecurityaffairs.comApr 7, 2026, 1:20 PM- SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 86Security Affairs
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Technical Deep Dive: The Monero Mining Campaign Operation Olalampo: Inside MuddyWater’s Latest Campaign VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731) Operation MacroMaze: new APT28 campaign using basic tooling and legit […]
newssecurityaffairs.comMar 1, 2026, 10:30 AM A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Canadian Tire 2025 data breach impacts 38 million users Iran ’s Internet near-totally blacked out amid […]
newssecurityaffairs.comMar 1, 2026, 12:35 AMAttackers are exploiting CVE-2026-1731 in BeyondTrust RS and PRA to deploy VShell, gain persistence, move laterally, and control compromised systems. Threat actors are actively exploiting a recently disclosed critical vulnerability, tracked as CVE-2026-1731 (CVSS score: 9.9), in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA). The flaw is being used to conduct a wide […]
newssecurityaffairs.comFeb 23, 2026, 12:09 PMCISA has updated its KEV entry for CVE-2026-1731 to alert organizations of exploitation in ransomware attacks.
newswww.securityweek.comFeb 20, 2026, 12:29 PM- VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)Unit42
CVE-2026-1731 is an RCE vulnerability in identity platform BeyondTrust. This flaw allows attackers control of systems without login credentials.
vendorunit42.paloaltonetworks.comFeb 19, 2026, 11:00 PM - 16th February – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 16th February, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Dutch telecom provider Odido was hit by a data breach following unauthorized access to its customer management system. Attackers extracted personal data of 6.2 million customers, including names, addresses, phone numbers, email […]
vendorresearch.checkpoint.comFeb 16, 2026, 5:57 PM A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Fintech firm Figure disclosed data breach after employee phishing attack U.S. CISA adds a flaw in […]
newssecurityaffairs.comFeb 15, 2026, 1:25 PM- Week in review: Exploited newly patched BeyondTrust RCE, United Airlines CISO on building resilienceHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: United Airlines CISO on building resilience when disruption is inevitable In this Help Net Security interview, Deneen DeFiore, VP and CISO at United Airlines, explains how the company approaches modernization without compromising safety-critical environments, why resilience and continuity matter as much as prevention, and how the airline manages risk across an interconnected ecosystem of vendors, partners, and infrastructure providers. What … More →
newswww.helpnetsecurity.comFeb 15, 2026, 9:00 AM - U.S. CISA adds a flaw in BeyondTrust RS and PRA to its Known Exploited Vulnerabilities catalogSecurity Affairs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in BeyondTrust RS and PRA to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an BeyondTrust RS and PRA vulnerability, tracked as CVE-2026-1731 (CVSS score of 9.9), to its Known Exploited Vulnerabilities (KEV) catalog. This week BeyondTrust released security updates to […]
newssecurityaffairs.comFeb 14, 2026, 3:54 PM Researchers warn that a critical vulnerability patched this week in BeyondTrust Remote Support is being exploited in the wild to compromise self-hosted deployments, including Bomgar remote support appliances, which included affected versions of the impacted software. Bomgar, a provider of privileged identity and access management products, acquired BeyondTrust in 2018, adopting the latter’s brand name. […]
newswww.csoonline.comFeb 13, 2026, 11:21 PMAttackers quickly targeted BeyondTrust flaw CVE-2026-1731 after a PoC was released, enabling unauthenticated remote code execution. Threat actors rapidly began exploiting a newly patched BeyondTrust vulnerability, tracked as CVE-2026-1731 (CVSS score of 9.9), soon after a proof-of-concept exploit became public. This week BeyondTrust released security updates to address the critical flaw in its Remote Support […]
newssecurityaffairs.comFeb 13, 2026, 3:19 PMExploitation attempts target CVE-2026-1731, a critical unauthenticated remote code execution flaw in BeyondTrust Remote Support.
newswww.securityweek.comFeb 13, 2026, 11:01 AMAttackers are exploiting a recently patched critical vulnerability (CVE-2026-1731) in internet-facing BeyondTrust Remote Support and Privileged Remote Access instances. “Attackers are abusing get_portal_info to extract the x-ns-company value before establishing a WebSocket channel,” Ryan Dewhurst, Head of Threat Intelligence at watchTowr, confirmed on Thursday. Rapid7 researchers published a technical analysis and proof-of-concept (PoC) exploit for CVE-2026-1731 on Tuesday, Feb. 10. Defused and GreyNoise have also detected widespread reconnaissance and limited exploitation activity. “So far we … More →
newswww.helpnetsecurity.comFeb 13, 2026, 10:45 AM- Reconnaissance Has Begun for the New BeyondTrust RCE (CVE-2026-1731): Here's What We See So FarGreyNoise
A PoC for CVE-2026-1731 hit GitHub on Feb 10. Within 24 hours, GreyNoise observed reconnaissance probing for vulnerable BeyondTrust instances.
vendorwww.greynoise.ioFeb 12, 2026, 12:00 AM - CVE-2026-1731Horizon3.ai
BeyondTrust Privileged Remote Access and Remote Support | Pre-Auth Remote Code Execution
exploithorizon3.aiFeb 11, 2026, 9:55 PM Companies using self-hosted versions of BeyondTrust Remote Support (RS) or Privileged Remote Access (PRA) should deploy patches for a critical vulnerability that allows attacks to execute OS commands without authentication. “Successful exploitation requires no authentication or user interaction and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption,” BeyondTrust said in […]
newswww.csoonline.comFeb 10, 2026, 11:22 PM- BeyondTrust Patches Critical RCE VulnerabilitySecurityWeek
Affecting both RS and PRA, the bug can be exploited remotely via crafted requests without authentication.
newswww.securityweek.comFeb 10, 2026, 11:24 AM BeyondTrust patched a critical pre-auth flaw in Remote Support and PRA that could let attackers execute code remotely. BeyondTrust released security updates to address a critical flaw, tracked as CVE-2026-1731 (CVSS score of 9.9), in its Remote Support and older Privileged Remote Access products. The bug could allow an unauthenticated attacker to send specially crafted […]
newssecurityaffairs.comFeb 9, 2026, 7:52 PM- BeyondTrust fixes easy-to-exploit pre-auth RCE vulnerability in remote access tools (CVE-2026-1731)Help Net Security
BeyondTrust fixed a critical remote code execution vulnerability (CVE-2026-1731) in its Remote Support (RS) and Privileged Remote Access (PRA) solutions and is urging self-hosted customers to apply the patch as soon a possible. Unlike the Remote Support zero-day (CVE-2024-12356) that was flagged after having been exploited by China-nexus threat actors to breach the US Treasury Department in late 2024, this newest vulnerability was discovered and privately disclosed by a security researcher. About CVE-2026-1731 BeyondTrust Privileged … More →
newswww.helpnetsecurity.comFeb 9, 2026, 11:36 AM No excerpt available.
Mitigationwww.cisa.govFeb 6, 2026, 10:16 PM- https://github.com/win3zz/CVE-2026-1731github.com
No excerpt available.
Exploitgithub.comFeb 6, 2026, 10:16 PM - https://www.beyondtrust.com/trust-center/security-advisories/bt26-02www.beyondtrust.com
No excerpt available.
Vendor Advisorywww.beyondtrust.comFeb 6, 2026, 10:16 PM - https://beyondtrustcorp.service-now.com/csm?id=csm_kb_article&sysparm_article=KB0023293beyondtrustcorp.service-now.com
No excerpt available.
Permissions Requiredbeyondtrustcorp.service-now.comFeb 6, 2026, 10:16 PM ses Fall Short GreyNoise Research Feb 24, 2026 GreyNoise Research Reconnaissance Has Begun for the New BeyondTrust RCE (CVE-2026-1731): Here's What We See So Far Glenn Thorpe Feb 12, 2026 GreyNoise Research The Noise in the Silence: Unmasking CISA's Hidden KEV Ransomware Updates Glenn Thorpe Feb 2, 2026 GreyNoise Research Products GreyNoise Platform G
vendorwww.greynoise.ioJan 8, 2026, 12:00 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2024-12686CVSS 6.6 · Medium
A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject command…
- CVE-2026-40141CVSS 8.5 · High
A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameter…
- CVE-2026-40140CVSS 8.7 · High
BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the network communication subsystem. Insufficient validation of…
- CVE-2026-40139CVSS 9.2 · Critical
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unaut…
- CVE-2026-40138CVSS 9.2 · Critical
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authenticatio…
- CVE-2025-5309CVSS 8.6 · High
The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code execut…