By vendor

Beyondtrust vulnerabilities

Known CVEs affecting Beyondtrust products, prioritized by severity, with SEC.co remediation and detection guidance.

2 published vulnerabilities

  • CVE-2026-40138HIGH 8.1

    BeyondTrust Remote Support and Privileged Remote Access contain a critical flaw in how they validate authentication credentials before a user logs in. An attacker on the network can exploit this weakness to bypass normal login protections and gain unauthorized access to the appliance, potentially including high-privilege accounts. The vulnerability only affects systems where a specific authentication configuration is enabled, which limits but does not eliminate the risk footprint.

  • CVE-2026-40140HIGH 7.5

    BeyondTrust Remote Support and Privileged Remote Access contain a pre-authentication denial-of-service vulnerability in their network communication layer. An unauthenticated attacker can send specially crafted input to crash or degrade appliance availability without needing valid credentials. The vulnerability stems from insufficient validation of client-supplied data before processing. This affects both products across versions prior to vendor patches.