Malicious actors have begun exploiting a recently disclosed security vulnerability affecting BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) products

“ Overnight we observed the first real-world exploitation of the BeyondTrust vulnerability through our global sensors Attackers are exploiting get_portal_info , to extract the x-ns-company value before creating a WebSocket channel ” said Ryan Dewhurst , head of threat intelligence at watchTowr . “ .”
See also: CISA: 6 new Microsoft vulnerabilities in the KEV Catalog
The vulnerability is tracked as CVE-2026-1731 (CVSS score: 9.9) and could allow an unauthenticated attacker to achieve remote code execution by sending specially crafted requests.
BeyondTrust noted last week that successful exploitation of the vulnerability could allow execution of operating system commands in the context of the site user, leading to unauthorized access, data exfiltration, and service disruption.
See also: ICS Patch Tuesday: Vulnerabilities fixed by Siemens, Schneider, Aveva, Phoenix Contact

BeyondTrust Vulnerability: Security Updates
The vulnerability was fixed in the following versions:
- Remote Support – Update BT26-02-RS, 25.3.2 and later versions
- Privileged Remote Access – Update BT26-02-PRA, 25.1.1 and later versions
The company has urged self-hosted Remote Support and Privileged Remote Access customers to manually apply the fixif they don't have automatic updates enabled. Those using a version of Remote Support earlier than 21.3 or Privileged Remote Access earlier than 22.1 are also required to upgrade to a newer version to apply this fix.
See also: Hackers exploit SolarWinds WHD vulnerabilities

The use of CVE-2026-1731 shows how quickly malicious actors can exploit new vulnerabilities, significantly reducing the time window for defenders to update critical systems.
Security vulnerabilities in BeyondTrust Privileged Remote Access and Remote Support have been exploited by cybercriminals in the past, so it is essential that users update to the latest version as soon as possible.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
