INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support

| 2026-07-07 08:12 HIGH LOW EXPLOITED VULNERABILITY VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
A critical pre-authentication remote code execution vulnerability affecting Remote Support and Privileged Remote Access appliances (CVE-2026-1731) was exploited on July 7, 2026, to establish WebSocket channels and deploy ransomware on vulnerable systems. The attack is attributed to the Chinese hacking group BeyondTrust, which targeted U.S. government agencies and compromised their systems in a previous incident linked to the Silk Typhoon cyberespionage group two years ago. Nearly 2,000 BeyondTrust RS and PRA instances were exposed online, but it's unclear how many have been patched against these flaws. The attack works by exploiting the vulnerabilities to bypass authentication and gain unauthorized access to targeted appliances, including accounts with elevated privileges. As of April 21, 2026, a patch has been applied to all RS/PRA cloud customers, while self-hosted customers are advised to apply the April security rollup patch or upgrade to RS 25.3.3 & above or PRA 25.3.3 & above.
Technical Mitigations AI-generated
• Patch BeyondTrust RS and PRA versions 25.3.2 or earlier to address CVE-2026-40138, which enables attackers without privileges to bypass access controls. • Use a network traffic analyzer like Wireshark to detect improper processing of BeyondTrust RS authentication requests, enabling unauthenticated remote attackers to gain unauthorized access (technique). • Block or hunt for suspicious WebSocket channels established by exploiting CVE-2026-1731.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-40140CVE-2026-40140 CVE-2026-40141CVE-2026-40141 CVE-2026-1731CVE-2026-1731 CVE-2026-40138CVE-2026-40138 CVE-2024-12686CVE-2024-12686 CVE-2024-12356CVE-2024-12356 CVE-2026-40139CVE-2026-40139
Target & Sectors
NORTH_AMERICA NORTH_AMERICA governmentgovernment
Incident Timeline
‎2026/07/07
Threat actors exploited critical pre-authentication vulnerabilities in BeyondTrust Remote Support and Privileged Remote Access to establish WebSocket channels, deploy ransomware, and target sensitive US government entities.
infrastructure 25.3.2
infrastructure 25.3.3
Tactical Metrics
Metrics
infrastructure
‎25.3.2
Software Version
Metrics
infrastructure
‎25.3.3
Software Version
Intelligence Sources