More

    BeyondTrust RCE flaw lets hackers run code without logging in



    • BeyondTrust warns of critical RCE flaw CVE-2026-1731 in RS and PRA
    • Vulnerability allows unauthenticated OS command execution, risking compromise and data exfiltration
    • Patch released February 2, 2026; ~11,000 instances exposed, mostly on-prem deployments

    American cybersecurity company BeyondTrust warned its customers that its Remote Support (RS) product, as well as certain older versions of Privileged Remote Access (PRA), are vulnerable to a remote code execution flaw that allows threat actors to run OS commands in the context of the site user.

    In a security advisory published on the company’s page earlier this week, BeyondTrust said that the bug, stemming from an OS command injection weakness, is tracked as CVE-2026-1731, and was given a severity score of 9.9/10 (critical).


    https://cdn.mos.cms.futurecdn.net/37uyEphcLreEFNUVCQzurn-2560-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img