hacker-news · Crawled Jul 7, 2026
BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA
Read original article ↗AI Summary
BeyondTrust has patched multiple critical vulnerabilities in its Remote Support (RS) and Privileged Remote Access (PRA) products. The most severe flaws, CVE-2026-40138 and CVE-2026-40139, allow unauthenticated attackers to bypass authentication and gain unauthorized access to appliances, including elevated privilege accounts, under specific configurations. Additional vulnerabilities could lead to denial-of-service conditions and unauthorized data access. While no active exploitation has been reported, past flaws in these products have been actively exploited to deploy web shells and backdoors, underscoring the urgency of patching.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.