A Critical Security Flaw Exposes Remote Access Software to Attackers
In a stark reminder of the ongoing cat-and-mouse game between security vendors and hackers, BeyondTrust has issued a warning to customers about two critical vulnerabilities in its remote access software. The flaws, which affect the company’s Remote Support (RS) and Privileged Remote Access (PRA) platforms, could allow attackers to bypass authentication and gain unauthorized access to targeted systems.
The first vulnerability, tracked as CVE-2026-40138, lies in an improper authentication weakness within the authentication subsystem of BeyondTrust’s RS remote desktop and assistance platform. This weakness can be exploited by attackers without privileges, allowing them to bypass access controls and access accounts with elevated privileges. The second flaw, identified as CVE-2026-40139, affects the processing of BeyondTrust RS authentication requests, enabling unauthenticated remote attackers to gain unauthorized access to vulnerable instances.
To make matters worse, these vulnerabilities can only be exploited if a specific authentication configuration is enabled, but the exact details of this configuration are not publicly disclosed. In addition to these two critical flaws, BeyondTrust has also released security updates for two high-severity issues (CVE-2026-40140 and CVE-2026-40141) that could allow attackers to trigger denial-of-service or access restricted resources on unpatched RS and PRA instances.
BeyondTrust emphasizes the severity of these vulnerabilities, stating that they may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance under specific configurations. The company has taken proactive steps by releasing patches for all affected customers, including those with self-hosted installations. However, it’s essential for security teams to take immediate action and apply the necessary updates to prevent exploitation.
The discovery of these vulnerabilities serves as a stark reminder that even well-established security vendors can be vulnerable to critical flaws. The fact that other security flaws affecting BeyondTrust’s remote support software have been exploited in the wild in recent years raises concerns about the potential for these vulnerabilities to be used by attackers. For instance, a critical pre-authentication remote code execution vulnerability (CVE-2026-1731) was recently exploited to establish WebSocket channels and deploy ransomware on vulnerable systems.
In light of this warning, security teams must prioritize patching and updating their remote access software to prevent exploitation. This incident serves as a stark reminder that vulnerabilities can be lurking in the shadows, waiting to be discovered by attackers. By staying vigilant and proactive, we can mitigate these risks and protect our networks from potential attacks.
Source: Bleeping Computer — 2026-07-07