Vendor

BeyondTrust

As of , 3 BeyondTrust vulnerabilities are on CISA's list of exploited vulnerabilities, 1 of them used in ransomware campaigns; 1 was added in 2026. Patch first: CVE-2026-1731.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2026-1731OS Command InjectionBeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)Patch nowRansomware use, listed within a year; Metasploit module0.91
2CVE-2024-12356Command InjectionBeyondTrust Privileged Remote Access (PRA) and Remote Support (RS)Patch this weekMetasploit module; EPSS 0.870.87
3CVE-2024-12686OS Command InjectionBeyondTrust Privileged Remote Access (PRA) and Remote Support (RS)Patch soon0.14

Products

  • Privileged Remote Access (PRA) and Remote Support (RS)2 entries
  • Remote Support (RS) and Privileged Remote Access (PRA)1 entry

Added each year

0.512024: 1120242025: 1120252026: 112026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20241
20251
20261

Used in ransomware

Changes CISA made to these entries

  1. CVE-2026-1731 BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)Ransomware use: Unknown to Known.

Every change we recorded