H-ISAC TLP White Threat Bulletin: Active Exploitation of BeyondTrust CVE-2026-1731
Palo Alto Networks Unit 42 recently published a report detailing the active, in-the-wild exploitation of CVE-2026-1731. The vulnerability is a pre-authentication remote code execution (RCE) flaw affecting BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA).
Threat actors are weaponizing this vulnerability to gain unauthorized control over appliances, facilitating broad malicious activities ranging from data theft to persistent network access. Users leveraging self-hosted instances of these products are urged to apply available patches to mitigate significant risk to operations.
Health-ISAC provides this information to increase situational awareness and encourage organizations to assess their level of risk to this vulnerability.
View the detailed report below.
For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact: