BeyondTrust has released crucial updates to fix vulnerabilities in its Remote Support (RS) and Privileged Remote Access (PRA) systems. These vulnerabilities can allow attackers to bypass authentication processes and obtain unauthorized access, posing a significant threat to users if left unpatched.
The first vulnerability (CVE-2026-40138) affects both RS and PRA systems in versions 25.3.2 or older. It allows unauthenticated attackers to circumvent access controls via an improper authentication weakness.
The second vulnerability (CVE-2026-40139) involves improper processing of authentication requests in BeyondTrust RS, enabling remote attackers to gain unauthorized access similar to the first flaw.
BeyondTrust has emphasized the critical nature of these vulnerabilities and is urging users to install the patches immediately to protect against potential unauthorized access and control attempts. Failure to do so could expose systems to abuse, particularly if certain authentication configurations are enabled.
In addition to addressing these critical issues, BeyondTrust has also issued updates for two high-severity vulnerabilities, further solidifying the security posture of their systems.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
BeyondTrust alerted customers about two critical vulnerabilities in its Remote Support and Privileged Remote Access software that could let attackers bypass authentication. Both vulnerabilities allow unauthorized access if specific authentication configurations are enabled, necessitating immediate patching by users of affected versions.
BeyondTrust released patches for critical vulnerabilities in its Remote Support and Privileged Remote Access products. Exploitation could allow attackers to gain unauthorized access and control over devices, posing significant security risks.