Vulnerabilities

Critical Flaws in BeyondTrust Remote Access Software

July 8, 2026 00:24 · 10 min read
Critical Flaws in BeyondTrust Remote Access Software

Critical Vulnerabilities in BeyondTrust Remote Access Software

BeyondTrust has warned its customers to patch two critical security flaws in its Remote Support (RS) and Privileged Remote Access (PRA) software. The vulnerabilities, tracked as CVE-2026-40138 and CVE-2026-40139, could allow attackers to bypass authentication and gain unauthorized access to targeted appliances, including accounts with elevated privileges.

Improper Authentication Weakness

The first vulnerability, CVE-2026-40138, affects the company's RS remote desktop and assistance platform (versions 25.3.2 or earlier) and the PRA enterprise cybersecurity solution (versions 25.3.2 or earlier). This vulnerability stems from an improper authentication weakness in the authentication subsystem, and successful exploitation enables attackers without privileges to bypass access controls and access targeted appliances.

Improper Processing of Authentication Requests

The second vulnerability, CVE-2026-40139, patched this week, stems from improper processing of BeyondTrust RS authentication requests, enabling unauthenticated remote attackers to gain unauthorized access to vulnerable instances. In both cases, BeyondTrust noted that exploitation also requires a specific authentication configuration to be enabled, but it didn't share further details.

BeyondTrust has also released security updates for two high-severity security issues (CVE-2026-40140 and CVE-2026-40141) that can be exploited to trigger denial-of-service or access restricted resources on unpatched RS and PRA instances.

"The most severe vulnerabilities may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance under specific configurations. Additional vulnerabilities may allow service disruption, unintended data access, and under distinct configurations, elevated access by an authenticated user that may impact system integrity," BeyondTrust said.

Patch and Mitigation

A patch has been applied to all RS/PRA cloud customers as of April 21, 2026. Self-hosted customers should apply the April security rollup patch for the affected version if their instance is not subscribed to automatic updates or upgrade to RS 25.3.3 & above or PRA 25.3.3 & above.

Exposure and Potential Attacks

Internet security watchdog group Shadowserver now tracks nearly 2,000 BeyondTrust RS and PRA instances exposed online, but there are no details on how many are honeypots or have already been patched against these flaws. While BeyondTrust didn't share any information about these flaws being abused in attacks before the patch, other security flaws affecting the company's remote support software have been exploited in the wild in recent years.

Silk Typhoon is believed to have exploited two zero-days (CVE-2024-12356 and CVE-2024-12686) to breach BeyondTrust's systems and use a stolen API key to compromise 17 Remote Support SaaS instances, including the Treasury's instance.

Conclusion

Security teams should prioritize patching these vulnerabilities and monitoring their systems for potential attacks. As BeyondTrust noted, "Test every layer before attackers do," and security teams should take a proactive approach to protect their systems and data.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free