Executive brief
BeyondTrust Remote Support and Privileged Remote Access solutions, which are used by organizations to provide secure remote technical support and manage administrative access, are affected by a critical security flaw. An unauthenticated attacker can remotely execute commands on the system, potentially leading to full system takeover, data theft, or service disruption. This vulnerability is reportedly being exploited in the wild, making immediate patching essential to protect corporate infrastructure.
Technical details
A critical OS command injection vulnerability (CWE-78) exists in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA). The flaw allows an unauthenticated remote attacker to execute arbitrary operating system commands in the context of the site user by sending specially crafted network requests. No user interaction or prior authentication is required for successful exploitation. The vulnerability has been observed in active exploitation. Patches are available in Remote Support version 25.3.2 and Privileged Remote Access version 25.1.
Affected products
- BeyondTrust Remote Support (RS) versions up to (excluding) 25.3.2
- BeyondTrust Privileged Remote Access (PRA) versions up to (excluding) 25.1
Timeline
- 2026-02-06: disclosed: Initial CVE entry received from BeyondTrust
- 2026-02-13: advisory: Vendor advisory and CISA KEV entry published
- 2026-02-13: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2026-02-13: exploited: Confirmed active exploitation in the wild