BeyondTrust warns of critical flaws in remote access software

BeyondTrust Warns of Critical Flaws in Remote Access Software, Urges Customers to Patch Immediately

A critical security alert has been issued by BeyondTrust, a leading provider of remote access software, warning customers of two severe vulnerabilities that could allow attackers to bypass authentication and gain unauthorized access to targeted systems. The flaws, tracked as CVE-2026-40138 and CVE-2026-40139, affect the company’s Remote Support (RS) and Privileged Remote Access (PRA) software, used by organizations worldwide for remote desktop assistance and cybersecurity solutions.

The vulnerabilities stem from improper authentication weaknesses in the software’s subsystems. In the case of CVE-2026-40138, attackers without privileges can bypass access controls and gain access to targeted appliances, including accounts with elevated privileges. Meanwhile, CVE-2026-40139 allows unauthenticated remote attackers to gain unauthorized access to vulnerable instances, provided a specific authentication configuration is enabled.

BeyondTrust has also released security updates for two high-severity issues, CVE-2026-40140 and CVE-2026-40141, which can be exploited to trigger denial-of-service or access restricted resources on unpatched RS and PRA instances. The company emphasizes that these vulnerabilities are particularly severe, allowing an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance under specific configurations.

The affected software versions include BeyondTrust RS 25.3.2 and earlier, as well as PRA 25.3.2 and earlier. Customers who have their instances subscribed to automatic updates are already protected, but self-hosted customers need to apply the April security rollup patch or upgrade to a newer version of the software.

This is not the first time BeyondTrust’s remote support software has been targeted by attackers. In recent years, several security flaws affecting the company’s software have been exploited in attacks. For instance, a critical pre-authentication remote code execution vulnerability (CVE-2026-1731) was used to establish WebSocket channels and deploy ransomware on vulnerable systems.

The exploitation of BeyondTrust vulnerabilities has also been linked to state-backed hacking groups. In 2024, the U.S. Treasury Department revealed that its network had been hacked by the notorious Chinese state-backed Silk Typhoon cyberespionage group. The attackers exploited two zero-days to breach BeyondTrust’s systems and use a stolen API key to compromise 17 Remote Support SaaS instances, including the Treasury’s instance.

The incidents highlight the importance of keeping software up-to-date and patching vulnerabilities promptly. Security teams should regularly review their systems for potential weaknesses and test every layer before attackers do. This includes conducting breach and attack simulation tests to ensure that SIEM and EDR rules are effective in detecting threats.

In light of this critical security alert, it is essential for customers using BeyondTrust’s remote access software to apply the recommended patches immediately. Self-hosted customers should prioritize upgrading their instances to the latest versions or applying the April security rollup patch to prevent potential attacks. By staying vigilant and proactive in addressing vulnerabilities, organizations can significantly reduce their risk of being compromised by attackers.


Source: Bleeping Computer — 2026-07-07