Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Advisory/Mitigation Exploitation Wave

BeyondTrust CVE-2026-1731 exploitation and remediation

Updated 20.02.2026 19:02
Case score 64
Case score 64 Members 3 Latest activity 20.02.2026 19:02
Active exploitation KEV: CISA KEV Patch status varies by member CVSS: 9.9 Critical
Members 3 First seen 09.02.2026 10:03 Last seen 20.02.2026 19:02 Updated 20.02.2026 19:02

Overview

**CVE-2026-1731** is being exploited in **BeyondTrust Remote Support** and **Privileged Remote Access**, where a pre-authentication OS command injection lets an unauthenticated attacker run commands in the site-user context. The activity affects self-hosted appliances on versions **25.3.1 and earlier** for Remote Support and **24.3.4 and earlier** for Privileged Remote Access, while watchTowr reported first in-the-wild abuse using **/get_portal_info** and **WebSocket** setup. BeyondTrust patched its SaaS service automatically and published **BT26-02-RS** and **BT26-02-PRA** for fixed on-premises versions, and CISA added the flaw to the **KEV catalog** with a three-day remediation deadline. Available evidence points to a wide exposure surface and active exploitation, but the full compromise scope is not quantified.

Signals

6 derived
Exploitation
Exploitation Active exploitation CVSS 9.9 Critical
CVEs/products
CVE
Remediation
Urgency Immediate Remediation KEV CISA KEV

Malware context

3 families

Member happenings

3 related
Vulnerability BeyondTrust Remote Support and Privileged Remote Access pre-auth OS command injection (CVE-2026-1731)
Updated 09.02.2026 10:03 Lead Contribution 61
CVSS 9.9 Critical Patch Patch Available

**CVE-2026-1731** is a **critical pre-authentication OS command injection** in **BeyondTrust Remote Support** and **Privileged Remote Access** that can let an **unauthenticated attacker** execute commands remotely in the site-user context. BeyondTrust patched **Remote Support 25.3.1 and earlier** and **Privileged Remote Access 24.3.4 and earlier**, with fixes in **BT26-02-RS / 25.3.2+** and **BT26-02-PRA / 25.1.1+**. Research published on **2026-02-13** says **watchTowr** observed **first in-the-wild exploitation** across its global sensors, with attackers abusing **get_portal_info** to extract **x-ns-company** before establishing a WebSocket channel. Successful exploitation can lead to **unauthorized access, data exfiltration, and service disruption**.

Exploitation Wave BeyondTrust Remote Support and Privileged Remote Access CVE-2026-1731 active exploitation wave
Updated 12.02.2026 23:34 Scoring Support Contribution 3
Exploitation Active Exploitation CVSS 9.9 Critical Patch Patch Available

**CVE-2026-1731** in **BeyondTrust Remote Support** and **Privileged Remote Access** is now seeing **first in-the-wild exploitation**, putting exposed appliances at risk of remote command execution. The activity targets **exposed portals** and abuses **/get_portal_info** to extract the **X-Ns-Company** value before establishing a WebSocket channel. Hacktron said about **11,000 instances** were exposed online, including roughly **8,500 on-premises deployments**, expanding the pool of systems at risk. Unpatched self-hosted appliances should be treated as high priority because the exploit requires **no authentication or user interaction**.

Advisory/Mitigation CISA KEV mitigation for BeyondTrust CVE-2026-1731
Updated 20.02.2026 19:02 Context
Exploitation Active Exploitation Urgency Immediate Patch Patch Available

CISA ordered urgent **KEV** mitigation for **CVE-2026-1731** in **BeyondTrust Remote Support** and **Privileged Remote Access**, forcing affected federal deployments to **apply the patch** or **stop using the product** within **three days**. The directive reflects active exploitation risk and turns the flaw into a mandatory remediation item. BeyondTrust customers running self-hosted systems must still **verify** or **install** the update, while the SaaS service was patched automatically.