CVE-2026-1731
BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.
- Published Feb 6, 2026
- CVSS 9.9 critical
- 90.9% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
- A Metasploit module exploits it
Affected software
In the news
- The vulnerabilities AI finds are the ones attackers want Help Net Security ·
- Google: AI Is Changing the Pace and Profile of Vulnerability Discovery SecurityWeek ·
- Vulnerability Discovery and Exploitation Trends in the AI Era Google Threat Intelligence ·
- Exploits and vulnerabilities in Q2 2026 Securelist ·
- Quantifying 2026 Routinely Targeted Vulnerabilities (So Far) VulnCheck Blog ·