BeyondTrust CVE-2026-1731 exploitation and remediation
Case score 64
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 64
- Main story score
- 61
- Related evidence lift
- +3 / 20
- Contributing updates
- 1
- Context updates
- 1
- Vulnerability Anchors the case with the critical pre-authentication BeyondTrust flaw and vendor remediation details. main
- Exploitation Wave Adds first-in-the-wild exploitation, the observed request sequence, and the exposure estimate. contributes
- Advisory Mitigation Provides KEV status and the three-day remediation deadline for the same BeyondTrust vulnerability. context
Overview
Latest development Open development history Exploitation first detected in BeyondTrust Remote Support Anomalous activity on a single BeyondTrust Remote Support appliance was linked to exploitation of CVE-2026-1731, with the first detected abuse dated January 31 before public disclosure of the flaw.
-
BeyondTrust releases fixes for CVE-2026-1731
BeyondTrust released advisory updates and patches for CVE-2026-1731 affecting Remote Support 25.3.1 and prior and Privileged Remote Access 24.3.4 and prior, with Remote Support fixed in BT26-02-RS, 25.3.2 and later, and Privileged Remote Access fixed in BT26-02-PRA, 25.1.1 and later; self-hosted customers were urged to manually apply the patch or upgrade older installations before remediation.
-
BeyondTrust discloses CVE-2026-1731
BeyondTrust publicly disclosed CVE-2026-1731 as a pre-authentication remote code execution vulnerability in BeyondTrust Remote Support and Privileged Remote Access, caused by an OS command injection weakness reachable through specially crafted client requests.
-
watchTowr reports first exploitation of exposed BeyondTrust portals
watchTowr reported first in-the-wild exploitation of exposed BeyondTrust portals on February 12, 2026, saying attackers were abusing /get_portal_info to extract the X-Ns-Company value before establishing a WebSocket channel and execute commands on vulnerable systems.