Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • BT26-02 current page
Link copied

BT26-02

Updated 2/13/26 at 6:06 p.m. EST. First published 2/6/26 at 5:15 p.m. EST.

Security Advisories

Advisory ID: BT26-02

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied
  • CVSSv4 score: 9.9
  • CVSSv4 Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:H/SA:L
  • Issue Date: 2026-02-06
  • Updated On: 2026-02-13
  • CVE: CVE-2026-1731
  • CWE: CWE-78
  • Synopsis: Remote code execution in Remote Support (RS) and Privileged Remote Access (PRA)
  • Affected Product: Remote Support (RS) and Privileged Remote Access (PRA)

Summary

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

BeyondTrust Remote Support and older versions of Privileged Remote Access contain a critical pre-authentication remote code execution vulnerability that may be triggered through specially crafted client requests. Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of the site user and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption.

Timeline Overview

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied
  • January 31, 2026 - BeyondTrust Security Team detects anomalous activity on a single Remote Support appliance. An external security researcher subsequently confirmed and validated this activity and reported the vulnerability in Remote Support and Privileged Remote Access to BeyondTrust. Triage and root cause analysis completed. Patch development begins.
  • February 2, 2026 - Patches (BT26-02-RS and BT26-02-PRA) issued and automatically deployed to all instances with BeyondTrust’s update service enabled. BeyondTrust SaaS instances fully patched.
  • February 3, 2026 - Knowledge article published on the customer portal advising customers to patch.
  • February 4, 2026 - Email notification sent to all active self-hosted customers who had not already patched.
  • February 6, 2026 - BeyondTrust Security Advisory (BT26-02) and CVE (CVE-2026-1731) published. Subsequent email notification sent to all active self-hosted customers who had not already patched.
  • February 10, 2026 - Initial exploitation attempt observed.
  • February 10, 2026 - Subsequent email notification sent to all active self-hosted customers who had not already patched.
  • Present - Continue to support customers in their patching, investigation, and response.

Details

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

BeyondTrust is aware of and supporting a limited number of self-hosted customers in responding to active exploitation attempts of the previously disclosed critical vulnerability (CVE-2026-1731) in its Remote Support and Privileged Remote Access solutions. The vulnerability has been patched, and BeyondTrust has automatically applied the update to all applicable instances with the BeyondTrust update service enabled. Active self-hosted customers were directly notified with instructions to download and apply the update.

Observed exploitation activity has been limited to internet-facing, self-hosted environments where the patch had not been applied before February 9, 2026.

Important: We are strongly encouraging all self-hosted customers who had internet-exposed instances that remained unpatched as of February 9 to take immediate action to apply the recommended updates and open a “Severity 1” ticket to BeyondTrust support, citing “BT26-02” in the description.

BeyondTrust’s investigation and support for customers remains ongoing. We are prioritizing rapid validation of new information and will continue to provide transparent updates as findings are confirmed. Protecting the security of our customers and their solutions remains our highest priority.

Mitigation

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

A patch has been applied to all Remote Support SaaS and Privileged Remote Access SaaS customers as of Feb 2, 2026 that remediates this vulnerability.

Self-hosted customers of Remote Support and Privileged Remote Access should manually apply the patch if their instance is not subscribed to automatic updates in their /appliance interface. Customers on a Remote Support version older than 21.3 or on Privileged Remote Access older than 22.1 will need to upgrade to a newer version to apply this patch.

Self-hosted customers of Privileged Remote Access may also upgrade to 25.1.1 or a newer version to remediate this vulnerability.

Self-hosted customers of Remote Support may also upgrade to 25.3.2 to remediate this vulnerability.

Affected Versions

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied
Product Affected Versions
Remote Support 25.3.1 and prior
Privileged Remote Access 24.3.4 and prior

Fixed Versions

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied
Product Remediation/Fix Available
Remote Support Patch BT26-02-RS (v21.3 - 25.3.1)
Remote Support 25.3.2 and greater
Privileged Remote Access Patch BT26-02-PRA (v22.1 - 24.X)
Privileged Remote Access 25.1 and greater

Acknowledgements

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

We would like to thank Harsh Jaiswal and the Hacktron AI team for responsibly disclosing this vulnerability to BeyondTrust. Hacktron AI identified this vulnerability through their novel approach to AI-enabled variant analysis. Their thorough research and cooperative engagement enabled us to investigate, remediate, and communicate this issue in a timely manner to help protect our customers.

References

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

https://www.cve.org/CVERecord?id=CVE-2026-1731

https://nvd.nist.gov/vuln/detail/CVE-2026-1731

https://beyondtrustcorp.service-now.com/csm?id=csm_kb_article&sysparm_article=KB0023293

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.