Emergent ThreatCVE-2026-1731:Critical Unauthenticated Remote Code Execution in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)Blog ↗
A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Beyondtrust | — | Upgrade BeyondTrust Remote Support to latest version.Upgrade BeyondTrust Privileged Remote Access to latest version. | Jul 21, 2025 | Dec 16, 2024 |
| Beyondtrust Pra | — | — | Feb 10, 2025 | Dec 17, 2024 |
| Beyondtrust Rs | — | — | Feb 10, 2025 | Dec 17, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub