Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Advisory/Mitigation Exploitation Wave

BeyondTrust CVE-2026-1731 exploitation and remediation

Updated 20.02.2026 19:02
Case score 64
Members 3 First seen 09.02.2026 10:03 Latest activity 20.02.2026 19:02

Overview

**CVE-2026-1731** is being exploited in **BeyondTrust Remote Support** and **Privileged Remote Access**, where a pre-authentication OS command injection lets an unauthenticated attacker run commands in the site-user context. The activity affects self-hosted appliances on versions **25.3.1 and earlier** for Remote Support and **24.3.4 and earlier** for Privileged Remote Access, while watchTowr reported first in-the-wild abuse using **/get_portal_info** and **WebSocket** setup. BeyondTrust patched its SaaS service automatically and published **BT26-02-RS** and **BT26-02-PRA** for fixed on-premises versions, and CISA added the flaw to the **KEV catalog** with a three-day remediation deadline. Available evidence points to a wide exposure surface and active exploitation, but the full compromise scope is not quantified.
Latest development Open development history 3 earlier developments Exploitation first detected in BeyondTrust Remote Support Anomalous activity on a single BeyondTrust Remote Support appliance was linked to exploitation of CVE-2026-1731, with the first detected abuse dated January 31 before public disclosure of the flaw.
  1. Earlier development

    BeyondTrust releases fixes for CVE-2026-1731

    BeyondTrust released advisory updates and patches for CVE-2026-1731 affecting Remote Support 25.3.1 and prior and Privileged Remote Access 24.3.4 and prior, with Remote Support fixed in BT26-02-RS, 25.3.2 and later, and Privileged Remote Access fixed in BT26-02-PRA, 25.1.1 and later; self-hosted customers were urged to manually apply the patch or upgrade older installations before remediation.

  2. Earlier development

    BeyondTrust discloses CVE-2026-1731

    BeyondTrust publicly disclosed CVE-2026-1731 as a pre-authentication remote code execution vulnerability in BeyondTrust Remote Support and Privileged Remote Access, caused by an OS command injection weakness reachable through specially crafted client requests.

  3. Earlier development

    watchTowr reports first exploitation of exposed BeyondTrust portals

    watchTowr reported first in-the-wild exploitation of exposed BeyondTrust portals on February 12, 2026, saying attackers were abusing /get_portal_info to extract the X-Ns-Company value before establishing a WebSocket channel and execute commands on vulnerable systems.

Signals

Impact signals
Exploitation
CVEs/products
Geographic context
Remediation

Threat actor context

5 listed

Malware context

3 families

Technical intelligence

Existing Case data

Member happenings

Vulnerability BeyondTrust Remote Support and Privileged Remote Access pre-auth OS command injection (CVE-2026-1731)
Updated 09.02.2026 10:03 Lead Contribution 61
CVSS 9.9 Critical Patch Patch Available

**CVE-2026-1731** is a **critical pre-authentication OS command injection** in **BeyondTrust Remote Support** and **Privileged Remote Access** that can let an **unauthenticated attacker** execute commands remotely in the site-user context. BeyondTrust patched **Remote Support 25.3.1 and earlier** and **Privileged Remote Access 24.3.4 and earlier**, with fixes in **BT26-02-RS / 25.3.2+** and **BT26-02-PRA / 25.1.1+**. Research published on **2026-02-13** says **watchTowr** observed **first in-the-wild exploitation** across its global sensors, with attackers abusing **get_portal_info** to extract **x-ns-company** before establishing a WebSocket channel. Successful exploitation can lead to **unauthorized access, data exfiltration, and service disruption**.

Exploitation Wave BeyondTrust Remote Support and Privileged Remote Access CVE-2026-1731 active exploitation wave
Updated 12.02.2026 23:34 Scoring Support Contribution 3
Exploitation Active Exploitation CVSS 9.9 Critical Patch Patch Available

**CVE-2026-1731** in **BeyondTrust Remote Support** and **Privileged Remote Access** is now seeing **first in-the-wild exploitation**, putting exposed appliances at risk of remote command execution. The activity targets **exposed portals** and abuses **/get_portal_info** to extract the **X-Ns-Company** value before establishing a WebSocket channel. Hacktron said about **11,000 instances** were exposed online, including roughly **8,500 on-premises deployments**, expanding the pool of systems at risk. Unpatched self-hosted appliances should be treated as high priority because the exploit requires **no authentication or user interaction**.

Advisory/Mitigation CISA KEV mitigation for BeyondTrust CVE-2026-1731
Updated 20.02.2026 19:02 Context
Exploitation Active Exploitation Urgency Immediate Patch Patch Available

CISA ordered urgent **KEV** mitigation for **CVE-2026-1731** in **BeyondTrust Remote Support** and **Privileged Remote Access**, forcing affected federal deployments to **apply the patch** or **stop using the product** within **three days**. The directive reflects active exploitation risk and turns the flaw into a mandatory remediation item. BeyondTrust customers running self-hosted systems must still **verify** or **install** the update, while the SaaS service was patched automatically.