BeyondTrust RS and PRA security alert: critical vulnerabilities allow access without authentication; updates to 25.3.3 immediately

Author: Published 4 min de lectura 135 reading

The images in this article were generated with artificial intelligence. How we publish

BeyondTrust has published patches for several critical vulnerabilities in its Remote Support (RS) and Privileged Remote Access (PRA) products that, in specific scenarios, allow remote attackers without authentication to avoid access controls and take control of affected devices. Among the failures are CVE-2026-40138 and CVE-2026-40139, both with CVSS score of 9.2 and related to authentication subsystem failures; CVE-2026-40140 (CVSS 8.7), which can cause denial of service by insufficient validation of network inputs; and CVE-2026-40141 (CVSS 8.5), which allows authenticated users with limited permits to access resources outside their scope. Gravity is high and exploitation could result in complete implementation commitments or service interruptions.

BeyondTrust indicates that the operation of CVE-2026-40138 and CVE-2026-40139 depends on a particular authentication configuration being enabled, and that CVE-2026-40141 requires accounts with specific permissions. However, the possibility of successful attacks requires prioritizing the response: the affected versions are RS and PRA 25.3.2 or lower, and the corrections are available in RS / PRA 25.3.3 and later. If you manage BeyondTrust applications, update to 25.3.3 or more as soon as possible. For details and guidelines of the supplier, see the official BeyondTrust security notices page: https: / / www.beyondtrust.com / company / security / advisory.

BeyondTrust RS and PRA security alert: critical vulnerabilities allow access without authentication; updates to 25.3.3 immediately
Image generated with IA.

The operating context increases the risk: similar remote support products have already been recurrent targets in campaigns that install web shells and back doors, as was the case with CVE-2024-12356 and CVE-2026-1731. Although BeyondTrust has not yet observed uses in real environments, history shows that vectors of access to administrative applications become privileged targets for actors seeking persistence and lateral movement. The exposure window should be closed quickly to prevent these vulnerabilities from being used as an entry point.

In addition to applying patches, it takes immediate compensatory measures: it restricts network access to the management interface by limiting it to management segmentation and VPNs, reviews and hardens authentication configurations that influence the operation according to the supplier's notes, and implements multifactor authentication for management accounts. It is also critical to review records and telemetry in search of unusual activity - unknown sessions, creation of new accounts, commands or atypical files - and to deploy web shells detection in affected perimeters. If the infrastructure allows, back up and test in an isolated environment before updating to avoid unplanned interruptions.

BeyondTrust RS and PRA security alert: critical vulnerabilities allow access without authentication; updates to 25.3.3 immediately
Image generated with IA.

After the update, complete operational mediation actions: broken administrative credentials that may have been exposed, restore keys and tokens if there is the least suspicion of commitment, and perform a basic forensic analysis of the applications to confirm absence of persistence. If you manage many devices, it prioritizes by exposure (Internet-accessible applications or connected to sensitive environments) and coordinates maintenance windows with business equipment. For individual CVE details and monitoring, see the NVD and the catalogue of exploited vulnerabilities known to CISA: https: / / nvd.nist.gov / vuln / detail / CVE-2026-40138 and https: / / www.cisa.gov / knowledge-exploited-vulnerabilities-catalog.

An additional point of editorial interest is that BeyondTrust attributes part of the finding to internal evaluations assisted by public IA models (e.g. Anthropic Claude Opus 4.8) along with its own tools. This illustrates how the IA accelerates vulnerability research but also raises the need for responsible validation and disclosure processes: automatic discovery accelerates the identification cycle, but organizations must have rigorous controls to avoid false positive and manage coordinated mitigation prior to public disclosure. Technology is accelerating, but governance and operational response remain the key factor in reducing risk.

In short, the immediate recommendation for security managers and equipment is clear: it plans and installs updates to RS / PRA 25.3.3 or higher, applies network and MFA restrictions, makes proactive detection of commitment signs and documents the actions taken. The combination of patches and mitigating operational controls is the best defense while the security community monitors if exploits appear in nature.

Coverage

Related

More news on the same subject.