Vendor
BeyondTrust
As of , 3 BeyondTrust vulnerabilities are on CISA's list of exploited vulnerabilities, 1 of them used in ransomware campaigns; 1 was added in 2026. Patch first: CVE-2026-1731.
Patch first
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1 | CVE-2026-1731OS Command Injection | BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) | Patch nowRansomware use, listed within a year; Metasploit module | 0.91 | ||
| 2 | CVE-2024-12356Command Injection | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) | Patch this weekMetasploit module; EPSS 0.87 | 0.87 | ||
| 3 | CVE-2024-12686OS Command Injection | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) | Patch soon | 0.14 |
Products
- Privileged Remote Access (PRA) and Remote Support (RS)2 entries
- Remote Support (RS) and Privileged Remote Access (PRA)1 entry
Added each year
Show the numbers
| Period | entries added |
|---|---|
| 2024 | 1 |
| 2025 | 1 |
| 2026 | 1 |
Used in ransomware
Changes CISA made to these entries
- CVE-2026-1731 BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)Ransomware use: Unknown to Known.