INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support
| 2026-07-07 08:12 HIGH LOW EXPLOITED VULNERABILITY VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
A critical pre-authentication remote code execution vulnerability affecting Remote Support and Privileged Remote Access appliances (CVE-2026-1731) was exploited on July 7, 2026, to establish WebSocket channels and deploy ransomware on vulnerable systems. The attack is attributed to the Chinese hacking group BeyondTrust, which targeted U.S. government agencies and compromised their systems in a previous incident linked to the Silk Typhoon cyberespionage group two years ago. Nearly 2,000 BeyondTrust RS and PRA instances were exposed online, but it's unclear how many have been patched against these flaws. The attack works by exploiting the vulnerabilities to bypass authentication and gain unauthorized access to targeted appliances, including accounts with elevated privileges. As of April 21, 2026, a patch has been applied to all RS/PRA cloud customers, while self-hosted customers are advised to apply the April security rollup patch or upgrade to RS 25.3.3 & above or PRA 25.3.3 & above.
Technical Mitigations AI-generated
• Patch BeyondTrust RS and PRA versions 25.3.2 or earlier to address CVE-2026-40138, which enables attackers without privileges to bypass access controls.
• Use a network traffic analyzer like Wireshark to detect improper processing of BeyondTrust RS authentication requests, enabling unauthenticated remote attackers to gain unauthorized access (technique).
• Block or hunt for suspicious WebSocket channels established by exploiting CVE-2026-1731.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-40140CVE-2026-40140
CVE-2026-40141CVE-2026-40141
CVE-2026-1731CVE-2026-1731
CVE-2026-40138CVE-2026-40138
CVE-2024-12686CVE-2024-12686
CVE-2024-12356CVE-2024-12356
CVE-2026-40139CVE-2026-40139
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
governmentgovernment
Incident Timeline
2026/07/07
Threat actors exploited critical pre-authentication vulnerabilities in BeyondTrust Remote Support and Privileged Remote Access to establish WebSocket channels, deploy ransomware, and target sensitive US government entities.
Click on any entity below to view its context and source!
infrastructure
25.3.2
The first vulnerability, tracked as
CVE-2026-40138
, affects the company's RS remote desktop and assistance platform (versions 25.3.2 or earlier) and the PRA enterprise cybersecurity solution (versions 25.3.2 or earlier).
"
The issues have been addressed in the following versions -
Remote Support RS 25.3.2 or lower (Fixed in RS 25.3.3 and above)
Privileged Remote Access PRA 25.3.2 or lower (Fixed in PRA 25.3.3 and above)
infrastructure
25.3.3
"
The issues have been addressed in the following versions -
Remote Support RS 25.3.2 or lower (Fixed in RS 25.3.3 and above)
Privileged Remote Access PRA 25.3.2 or lower (Fixed in PRA 25.3.3 and above)
Tactical Metrics
Metrics
infrastructure
25.3.2
Software Version
Click for context!
The first vulnerability, tracked as
CVE-2026-40138
, affects the company's RS remote desktop and assistance platform (versions 25.3.2 or earlier) and the PRA enterprise cybersecurity solution (versions 25.3.2 or earlier).
"
The issues have been addressed in the following versions -
Remote Support RS 25.3.2 or lower (Fixed in RS 25.3.3 and above)
Privileged Remote Access PRA 25.3.2 or lower (Fixed in PRA 25.3.3 and above)
Metrics
infrastructure
25.3.3
Software Version
"
The issues have been addressed in the following versions -
Remote Support RS 25.3.2 or lower (Fixed in RS 25.3.3 and above)
Privileged Remote Access PRA 25.3.2 or lower (Fixed in PRA 25.3.3 and above)
Intelligence Sources
BleepingComputer
2026-07-07
BeyondTrust warns of critical flaws in remote access software
BleepingComputer
The Hacker News
2026-07-07
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T12:24
Comprehensive Tactical Telemetry
Highly Correlated Entities
19x
organisation
Identified Entity
the Committee on Foreign Investment
entity
7x
vulnerability
Exploited CVE
CVE-2026-1731
cve
2x
tactic
Cyber Operation Type
Ransomware
tactic
2x
timeline
Temporal Reference
April 21, 2026
date
2x
infrastructure
Software Version
25.3.2
version
2x
general metric
%
54
%
2x
general metric
Jul
7
jul
Contextual Telemetry
Context Block
8 METRICS
target region
Target Country
United States
country
source region
Origin Country
China
country
industry
Targeted Sector
Government
sector
general metric
Saas Instances
17
saas instances
general metric
Beyondtrust Rs
2,000
beyondtrust rs
general metric
Vulnerabilities
9
vulnerabilities
general metric
40140 Cvss Score
9
40140 cvss score
general metric
Anthropic Claude Opus
5
anthropic claude opus
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.