Letter/Comment
H-ISAC TLP White Vulnerability Bulletin - BeyondTrust Disclosed Critical Flaw in Remote Support Software
On February 6, 2026, BeyondTrust released a security advisory, disclosing a critical pre-authentication Remote Code Execution (RCE) vulnerability tracked as CVE-2026-1731, affecting its Remote Support (RS) and Privileged Remote Access (PRA) products.
Analysis
CVE-2026-1731 is a critical flaw in the BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) software. The flaw has a CVSS score of 9.9. In the event of successful exploitation, an unauthenticated attacker could execute operating system commands remotely, resulting in full system compromise.
View the detailed report below.
For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact: