bleeping-computer · Crawled Jul 7, 2026

BeyondTrust warns of critical flaws in remote access software

1 Actors
Read original article ↗

AI Summary

BeyondTrust has disclosed two critical vulnerabilities, CVE-2026-40138 and CVE-2026-40139, in its Remote Support (RS) and Privileged Remote Access (PRA) software that allow unauthenticated attackers to bypass authentication and gain unauthorized access to affected systems. Exploitation requires specific configurations, though details were not disclosed. The vendor has patched cloud instances and urges self-hosted customers to update to version 25.3.3 or later. Previous vulnerabilities in the same software have been actively exploited in the wild by threat actors, including the Chinese state-backed group Silk Typhoon.

AI-extracted · verify before operational use

Extracted Entities 1 found