CISA: BeyondTrust RCE flaw now exploited in ransomware attacks

Hackers are actively exploiting the CVE-2026-1731 vulnerability in the BeyondTrust Remote Support product, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns.

BleepingComputer

DATE: February 20, 2026 at 05:05PM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

#Hospitals at Risk of #BeyondTrust #Ransomware Hacks: Critical Vulnerability Could Give Attackers Foothold into Clinical Networks https://t.co/O9bujrU6lu @HealthISAC @HHSGov

Here are any URLs found in the article text:

https://t.co/O9bujrU6lu

Articles can be found by scrolling down the page at https://www.healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: https://www.clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

Une #vulnérabilité critique activement exploitée dans #BeyondTrust RS. Plusieurs sociétés de #sécurité ont lancé des alertes après l’exploitation rapide d’une #faille critique (...)
https://www.lemondeinformatique.fr/actualites/lire-une-vulnerabilite-critique-activement-exploitee-dans-beyondtrust-rs-99399.html
Une vulnérabilité critique activement exploitée dans BeyondTrust RS - Le Monde Informatique

Ces attaques, détectées par des chercheurs, ont compromis des appliances de support à distance de Bomgar dont beaucoup ont atteint leur fin de vie....

LeMondeInformatique
CISA gives feds 3 days to patch actively exploited BeyondTrust flaw

CISA ordered U.S. government agencies on Friday to secure their BeyondTrust Remote Support instances against an actively exploited vulnerability within three days.

BleepingComputer
📢 Faille critique CVE-2026-1731 dans BeyondTrust exploitée pour prendre le contrôle d’Active Directory
📝 GBHackers Security rapporte qu’une campagne d’attaque exploite la vulnérabilité critique **CVE-2026-1...
📖 cyberveille : https://cyberveille.ch/posts/2026-02-16-faille-critique-cve-2026-1731-dans-beyondtrust-exploitee-pour-prendre-le-controle-dactive-directory/
🌐 source : https://gbhackers.com/attackers-exploit-critical-beyondtrust-flaw/
#BeyondTrust #CISA_KEV #Cyberveille
Faille critique CVE-2026-1731 dans BeyondTrust exploitée pour prendre le contrôle d’Active Directory

GBHackers Security rapporte qu’une campagne d’attaque exploite la vulnérabilité critique CVE-2026-1731 affectant des déploiements auto-hébergés de BeyondTrust Remote Support et Privileged Remote Access. La faille autorise des attaquants non authentifiés à réaliser une injection de commandes système, conduisant à une exécution de code à distance (RCE). Les produits concernés sont explicitement les instances auto-hébergées de BeyondTrust Remote Support et de Privileged Remote Access. ⚠️ L’impact mis en avant est majeur, les attaquants pouvant prendre un contrôle complet d’Active Directory, ce qui élargit drastiquement leur surface d’action au sein des environnements ciblés.

CyberVeille
U.S. CISA adds a flaw in BeyondTrust RS and PRA to its Known Exploited Vulnerabilities catalog

The U.S. CISA adds a vulnerability in BeyondTrust RS and PRA to its Known Exploited Vulnerabilities catalog.

Security Affairs
Attackers exploit BeyondTrust CVE-2026-1731 within hours of PoC release

Attackers quickly targeted BeyondTrust flaw CVE-2026-1731 after a PoC was released, enabling unauthenticated remote code execution.

Security Affairs
Critical BeyondTrust RCE flaw now exploited in attacks, patch now

A critical pre-authentication remote code execution vulnerability in BeyondTrust Remote Support and Privileged Remote Access appliances is now being exploited in attacks after a PoC was published online.

BleepingComputer
BeyondTrust warns of critical RCE flaw in remote support software

BeyondTrust warned customers to patch a critical security flaw in its Remote Support (RS) and Privileged Remote Access (PRA) software that could allow unauthenticated attackers to execute arbitrary code remotely.

BleepingComputer
BeyondTrust fixes critical pre-auth bug allowing remote code execution

BeyondTrust patched a critical pre-auth flaw in Remote Support and PRA that could let attackers execute code remotely.

Security Affairs