BeyondTrust has released updates to address a critical security vulnerability affecting its Remote Support (RS) and Privileged Remote Access (PRA) products. If successfully exploited, this vulnerability could lead to remote code execution.

“BeyondTrust Remote Support (RS) and some older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability,” said in an advisory issued on February 6, 2026.
“By sending specially crafted requests, an unauthenticated remote attacker can execute operating system commands as the site user“.
See also: Four new vulnerabilities in Ingress NGINX
The vulnerability, categorized as “OS command injection,” is tracked as CVE-2026-1731 and has received a CVSS score of 9.9/10.
Execution of malicious commands could lead to unauthorized access, data extraction, and service disruption.
BeyondTrust: Which versions are affected and fixes
Affected versions include:
– Remote Support version 25.3.1 and earlier
– Privileged Remote Access version 24.3.4 and earlier
The available fixes are:
– Remote Support – Patch BT26-02-RS, 25.3.2 and later versions
– Privileged Remote Access – Patch BT26-02-PRA, 25.1.1 and later versions

The company is urging self-hosted Remote Support and Privileged Remote Access customers to manually apply the fixif they don't have automatic updates enabled. Those using a version of Remote Support earlier than 21.3 or Privileged Remote Access earlier than 22.1 are also required to upgrade to a newer version to apply this fix.
See also: Claude Opus 4.6: Found 500+ bugs in open-source libraries
“Self-hosted customers can also upgrade to version 25.1.1 or later to resolve this vulnerability,” the company added.
According to security researcher and co-founder of Hacktron AI, Harsh Jaiswal, the vulnerability was discovered on January 31, 2026, through AI-enabled variant analysis, which identified approximately 11,000 exposed instances online.
“ About ~8,500 of these are on-prem installations, which remain potentially vulnerable if the fixes are not applied ,” Jaiswal said
See also: Attackers exploit old Windows vulnerability to disable EDR

Additional details of the vulnerability have not been published, to give users time to apply the fixes.
Security vulnerabilities in BeyondTrust Privileged Remote Access and Remote Support have been exploited by cybercriminals in the past, so it is essential that users update to the latest version as soon as possible.
