LIVE · cybersecurity feed
Live wire
Malware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentialsSix Maximum-Severity Flaws Found in Cisco ProductsCritical Isolated-vm Vulnerability Leads to RCE on Host
beyondtrustcritical

BeyondTrust warns of critical flaws in remote access software

BeyondTrust has alerted users to two critical vulnerabilities affecting its Remote Support and Privileged Remote Access software. These security weaknesses could potentially enable attackers to circumvent authentication mechanisms.

zeroday.news ·

BeyondTrust has issued a warning to its customers regarding two critical security vulnerabilities discovered in its Remote Support (RS) and Privileged Remote Access (PRA) software. These flaws could potentially allow attackers to bypass authentication mechanisms and gain unauthorized access to affected systems.

The first vulnerability, identified as CVE-2026-40138, impacts both Remote Support and Privileged Remote Access versions 25.3.2 and earlier. This issue resides within the authentication subsystem and is described as an improper authentication weakness. Successful exploitation of this flaw could enable an attacker without prior privileges to circumvent access controls and compromise targeted appliances, including those with elevated user accounts.

The second critical vulnerability, CVE-2026-40139, also affects the same versions of BeyondTrust's software. This flaw arises from the improper processing of authentication requests within the Remote Support component. It could permit unauthenticated remote attackers to achieve unauthorized access to vulnerable instances. BeyondTrust has indicated that both of these critical vulnerabilities require a specific authentication configuration to be enabled for successful exploitation, though further details on this configuration were not provided.

In addition to the critical vulnerabilities, BeyondTrust has also addressed two high-severity security issues, tracked as CVE-2026-40140 and CVE-2026-40141. These flaws, if exploited, could lead to denial-of-service conditions or unauthorized access to restricted resources on unpatched RS and PRA instances.

BeyondTrust stated that the most severe vulnerabilities could allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance under specific configurations. Other vulnerabilities may result in service disruption, unintended data access, and, under distinct configurations, elevated access for authenticated users, potentially impacting system integrity.

For cloud-based customers, BeyondTrust confirmed that a patch was applied to all RS/PRA cloud instances as of April 21, 2026. Customers hosting their own instances are advised to apply the April security rollup patch for the affected version if their systems are not configured for automatic updates. Alternatively, they should upgrade to RS version 25.3.3 or later, or PRA version 25.3.3 or later.

Internet security watchdog group Shadowserver is currently monitoring nearly 2,000 BeyondTrust RS and PRA instances accessible online. However, the exact number of these instances that are potentially vulnerable or have already been patched remains unclear, as some may be honeypots.

While BeyondTrust has not disclosed any instances of these specific vulnerabilities being actively exploited in attacks prior to the release of patches, the company's remote support software has been a target in the past. Notably, a critical pre-authentication remote code execution vulnerability in Remote Support and Privileged Remote Access appliances (CVE-2026-1731) was previously exploited to establish WebSocket channels and deploy ransomware.

Past security incidents involving BeyondTrust software have also been linked to sophisticated cyberespionage operations. For example, the U.S. Treasury Department reported a network breach attributed to the Chinese state-backed Silk Typhoon group, which is believed to have exploited two zero-day vulnerabilities (CVE-2024-12356 and CVE-2024-12686) in BeyondTrust systems. This breach allowed the group to use a stolen API key to compromise multiple Remote Support SaaS instances, including those belonging to the Treasury, the Committee on Foreign Investment in the United States (CFIUS), and the Office of Foreign Assets Control (OFAC).

beyondtrustremote supportprivileged remote accessvulnerabilityauthentication bypass
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Postal Service moves to finalize mail ballot regs before SCOTUS ruling

The rules have already been rejected by multiple state courts, but the Trump administration said it’s preparing in case of a favorable Supreme Court decision. The post Postal Service moves to finalize mail ballot regs before SCOTUS ruling appeared first on CyberScoop.

vulnerability

ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries

ToxicPanda 2.0 targets 349 financial apps and abuses Android Wireless Debugging to gain deeper device access and steal banking credentials. ToxicPanda used to be a Europe-focused nuisance targeting a manageable list of banks. That version is gone. Zimperium’s zLabs team just documented ToxicPanda 2.0, and the numbers alone tell the story: 349 targeted financial institutions […]

ai

If you're not using AI to attack your own systems, your adversaries will

Agents are also the new attack surface - cue defenders' existential angst

privacy

TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit

TikTok has agreed to a $400 million settlement with the U.S. Department of Justice to resolve a lawsuit alleging violations of child privacy laws. The lawsuit, filed in 2024, accused the company of improperly collecting data from users under 13 and failing to comply with parental requests to delete accounts. The settlement includes an immediate payment of $300 million and an additional $100 million contingent on the dissolution of a prior consent decree related to Musical.ly.

malware

Hackers infect Android car head units with proxy botnet malware

A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. [...]

security

Named Pipes Under Attack: Securing Windows Interprocess Communication

Windows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes. ThreatLocker explains how endpoint verification, command authorization, strict input validation, and narrowly scoped privileges can help secure named-pipe communication. [...]