Signal

BeyondTrust patches critical pre-auth RCE (CVE-2026-1731) in RS and PRA

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-02-09 19:05 UTCUpdated 2026-02-10 11:24 UTC
rss
cvercevulnerabilitypatchingremote_access_tools
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.
2 top sources shown
BeyondTrust Patches Critical RCE Vulnerability
SecurityWeek · News · securityweek.com · 2026-02-10 11:24 UTC
limited source diversity in top sources
Overview

BeyondTrust released fixes for CVE-2026-1731, a critical pre-authentication remote code execution vulnerability affecting Remote Support (RS) and Privileged Remote Access (PRA).

Entities
BeyondTrustSecurityWeekHacktron AI
Score total
1.01
Momentum 24h
2
Posts
2
Origins
2
Source types
1
Duplicate ratio
0%
Why now
  • BeyondTrust issued an advisory and patches in early February 2026
  • Fresh reporting consolidates exploitability details and affected products
  • Patch status differs between SaaS (auto) and on-prem (manual)
Why it matters
  • Pre-auth RCE enables remote command execution without credentials
  • Self-hosted RS/PRA instances remain exposed until manually updated
  • Remote access tooling is high-impact if compromised
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
  • CVE-2026-1731 is a critical pre-authentication RCE in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) exploitable via crafted requests without authentication.
  • BeyondTrust automatically patched SaaS instances, while self-hosted customers must apply updates manually to remediate exposure.
  • Rapid7 reports BeyondTrust had not reported active exploitation in the wild at the time of disclosure.
How sources frame it
  • Rapid7: neutral
  • SecurityWeek: neutral
Two-source cluster on a newly disclosed BeyondTrust pre-auth RCE (CVE-2026-1731) with patch guidance and deployment risk split between SaaS and self-hosted.
All evidence
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
  • SecurityWeek (1)
  • Rapid7 Blog (1)
Top origin domains (this list)
  • securityweek.com (1)
  • rapid7.com (1)