Security
Critical BeyondTrust Vulnerability Exploited in Ransomware Campaigns
CISA Warns of Ransomware Attacks Exploiting BeyondTrust RCE Flaw
A critical vulnerability, CVE-2026-1731, in BeyondTrust’s Remote Support product is being actively exploited by hackers, as highlighted by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
The security flaw impacts versions Remote Support 25.3.1 and earlier, as well as Privileged Remote Access 24.3.4 and earlier, enabling remote code execution.
CISA swiftly added this vulnerability to the Known Exploited Vulnerabilities (KEV) catalog on February 13, urging federal agencies to apply the patch or discontinue product usage within three days.
BeyondTrust initially disclosed CVE-2026-1731 on February 6, categorizing it as a pre-authentication remote code execution vulnerability stemming from an OS command injection flaw, exploitable through specially crafted client requests.
Shortly after its disclosure, proof-of-concept (PoC) exploits surfaced, leading to immediate in-the-wild exploitation.
By February 13, BeyondTrust updated the bulletin to reveal exploitation detection on January 31, effectively making CVE-2026-1731 a zero-day vulnerability for at least a week.
According to BeyondTrust, researcher Harsh Jaiswal and the Hacktron AI team’s report verified anomalous activity on a single Remote Support appliance during that period.
CISA has activated the ‘Known To Be Used in Ransomware Campaigns?’ indicator in the KEV catalog in response to the situation.
Cloud-based application (SaaS) customers were automatically patched on February 2, requiring no manual intervention. Self-hosted instances must either enable automatic updates or verify patch application through the ‘/appliance’ interface.
For Remote Support, upgrading to version 25.3.2 is recommended, while Privileged Remote Access users should transition to version 25.1.1 or newer.
Users still on RS v21.3 and PRA v22.1 are advised to upgrade to a more recent version before applying the patch.
Modern IT infrastructure outpaces manual workflows. Discover how to reduce delays and enhance reliability with automated responses in the new Tines guide.
Learn to build and scale intelligent workflows on existing tools for improved efficiency.
-
Facebook4 months agoEU Takes Action Against Instagram and Facebook for Violating Illegal Content Rules
-
Facebook4 months agoWarning: Facebook Creators Face Monetization Loss for Stealing and Reposting Videos
-
Facebook4 months agoFacebook Compliance: ICE-tracking Page Removed After US Government Intervention
-
Facebook4 months agoInstaDub: Meta’s AI Translation Tool for Instagram Videos
-
Facebook2 months agoFacebook’s New Look: A Blend of Instagram’s Style
-
Facebook2 months agoFacebook and Instagram to Reduce Personalized Ads for European Users
-
Facebook3 months agoReclaim Your Account: Facebook and Instagram Launch New Hub for Account Recovery
-
Apple4 months agoMeta discontinues Messenger apps for Windows and macOS

