← All stories
● Covered by 2 sources · 2 reportsMedium impact

BeyondTrust Patches Critical Vulnerabilities in Remote Support Products

🔄 Updated 87d ago — new reporting from BleepingComputer
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • BeyondTrust patched CVE-2026-40138 and CVE-2026-40139.
  • Vulnerabilities allow unauthorized access if exploited.
  • Critical for users to apply updates immediately.
  • Issues exist in Remote Support and Privileged Remote Access software.
  • Flaws affect versions 25.3.2 or earlier.

Overview of BeyondTrust Vulnerabilities

BeyondTrust has released crucial updates to fix vulnerabilities in its Remote Support (RS) and Privileged Remote Access (PRA) systems. These vulnerabilities can allow attackers to bypass authentication processes and obtain unauthorized access, posing a significant threat to users if left unpatched.

Specific Vulnerabilities and Their Risks

The first vulnerability (CVE-2026-40138) affects both RS and PRA systems in versions 25.3.2 or older. It allows unauthenticated attackers to circumvent access controls via an improper authentication weakness.

The second vulnerability (CVE-2026-40139) involves improper processing of authentication requests in BeyondTrust RS, enabling remote attackers to gain unauthorized access similar to the first flaw.

Call to Action for Immediate Patching

BeyondTrust has emphasized the critical nature of these vulnerabilities and is urging users to install the patches immediately to protect against potential unauthorized access and control attempts. Failure to do so could expose systems to abuse, particularly if certain authentication configurations are enabled.

Additional Security Enhancements

In addition to addressing these critical issues, BeyondTrust has also issued updates for two high-severity vulnerabilities, further solidifying the security posture of their systems.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

BeyondTrust alerted customers about two critical vulnerabilities in its Remote Support and Privileged Remote Access software that could let attackers bypass authentication. Both vulnerabilities allow unauthorized access if specific authentication configurations are enabled, necessitating immediate patching by users of affected versions.

BeyondTrust released patches for critical vulnerabilities in its Remote Support and Privileged Remote Access products. Exploitation could allow attackers to gain unauthorized access and control over devices, posing significant security risks.