HomeSecurityBeyondTrust: Critical vulnerabilities in Remote Support and PRA

BeyondTrust: Critical vulnerabilities in Remote Support and PRA

BeyondTrust has released emergency security updates to address four critical vulnerabilities affecting its Remote Support (RS) and Privileged Remote Access (PRA) products . Two of the vulnerabilities are rated critical with a CVSS score of 9.2 and could allow unauthorized attackers to gain complete control of affected devices without any prior authentication. The company stressed that there is no evidence of active exploitation, but the history of its products makes applying the fixes an immediate priority.

BeyondTrust Remote Support auth bypass vulnerabilities CVE-2026-40138

Specifically, CVE-2026-40138 (CVSS: 9.2) concerns a pre-authentication in the authentication subsystem of both Remote Support and Privileged Remote Access. The vulnerability results from inadequate validation of authentication data, allowing an attacker located on the network to bypass checks and gain unauthorized access to the device, including accounts with elevated privileges. Similarly, CVE-2026-40139 (CVSS: 9.2) affects Remote Support and is related to inadequate processing of authentication requests, which could allow a remote attacker to bypass security mechanisms and gain access to highly privileged accounts.

See also: BeyondTrust patches critical RCE vulnerability in Remote Support and PRA

It is worth noting that successful exploitation of CVE-2026-40138 and CVE-2026-40139 depends on a specific authentication configuration being enabled. This means that not all installations are affected equally, but organizations using non-default authentication settings are at increased risk.

In addition to the two critical vulnerabilities, BeyondTrust has also disclosed two other serious security issues. CVE-2026-40140 (CVSS: 8.7) is located in the network communication subsystem and results from insufficient validation of client-supplied input. A remote, unauthorized attacker could exploit this vulnerability to cause a denial-of-service (DoS), affecting the availability of the device. Finally, CVE-2026-40141 (CVSS: 8.5) concerns a web application component in Remote Support and PRA, where insufficient validation of user data allows an authorized attacker with limited privileges to gain access to resources or data outside of their authorized scope.

Of particular interest is the fact that BeyondTrust discovered all of the vulnerabilities as part of ongoing security assessments, using publicly available artificial intelligence (AI) and proprietary research tools. This is a notable revelation, as it shows how cybersecurity companies are now leveraging AI to discover vulnerabilities in their own products — a practice that is expected to become increasingly widespread in the industry.

See also: BeyondTrust: Remote Support & Privileged Remote Access Vulnerability

BeyondTrust - SecNews.gr

BeyondTrust Remote Support: Exploit History and Risks

BeyondTrust ’s Remote Support and Privileged Remote Access products have been the target of repeated cyberattacks in the past. Vulnerabilities in these products have been used to install web shells and backdoors , allowing malicious actors to gain a permanent presence on corporate networks. Given that these products are widely used by organizations to provide remote support and manage privileged access, their exploitation can lead to serious data breaches and service disruptions.

The affected versions and fixes released by BeyondTrust are as follows: Remote Support RS 25.3.2 and earlier have been fixed in RS 25.3.3 and later, while Privileged Remote Access PRA 25.3.2 and earlier have been fixed in PRA 25.3.3 and later. Organizations using these products should upgrade immediately.

To protect their systems, security administrators should immediately apply the updates released by BeyondTrust, review their device authentication settings for any non-standard configurations that increase the risk of exploitation of CVE-2026-40138 and CVE-2026-40139, and monitor logs for suspicious activity. In addition, it is recommended to implement the principle of least privilege for accounts accessing Remote Support and PRA, as well as network segmentation to restrict access to these critical infrastructures.

See also: BeyondTrust: Hackers breached Remote Support SaaS tools

BeyondTrust: Critical vulnerabilities in Remote Support and PRA

Overall, BeyondTrust's new vulnerabilities are yet another reminder of the importance of promptly applying security updates, especially for products that manage privileged access to corporate networks. According to The Hacker News, the company has not identified any active exploits, but the history of its products makes it imperative for any organization using them to take immediate action.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS