The images in this article were generated with artificial intelligence. How we publish
BeyondTrust has published patches for several critical vulnerabilities in its Remote Support (RS) and Privileged Remote Access (PRA) products that, in specific scenarios, allow remote attackers without authentication to avoid access controls and take control of affected devices. Among the failures are CVE-2026-40138 and CVE-2026-40139, both with CVSS score of 9.2 and related to authentication subsystem failures; CVE-2026-40140 (CVSS 8.7), which can cause denial of service by insufficient validation of network inputs; and CVE-2026-40141 (CVSS 8.5), which allows authenticated users with limited permits to access resources outside their scope. Gravity is high and exploitation could result in complete implementation commitments or service interruptions.
BeyondTrust indicates that the operation of CVE-2026-40138 and CVE-2026-40139 depends on a particular authentication configuration being enabled, and that CVE-2026-40141 requires accounts with specific permissions. However, the possibility of successful attacks requires prioritizing the response: the affected versions are RS and PRA 25.3.2 or lower, and the corrections are available in RS / PRA 25.3.3 and later. If you manage BeyondTrust applications, update to 25.3.3 or more as soon as possible. For details and guidelines of the supplier, see the official BeyondTrust security notices page: https: / / www.beyondtrust.com / company / security / advisory.

The operating context increases the risk: similar remote support products have already been recurrent targets in campaigns that install web shells and back doors, as was the case with CVE-2024-12356 and CVE-2026-1731. Although BeyondTrust has not yet observed uses in real environments, history shows that vectors of access to administrative applications become privileged targets for actors seeking persistence and lateral movement. The exposure window should be closed quickly to prevent these vulnerabilities from being used as an entry point.
In addition to applying patches, it takes immediate compensatory measures: it restricts network access to the management interface by limiting it to management segmentation and VPNs, reviews and hardens authentication configurations that influence the operation according to the supplier's notes, and implements multifactor authentication for management accounts. It is also critical to review records and telemetry in search of unusual activity - unknown sessions, creation of new accounts, commands or atypical files - and to deploy web shells detection in affected perimeters. If the infrastructure allows, back up and test in an isolated environment before updating to avoid unplanned interruptions.

After the update, complete operational mediation actions: broken administrative credentials that may have been exposed, restore keys and tokens if there is the least suspicion of commitment, and perform a basic forensic analysis of the applications to confirm absence of persistence. If you manage many devices, it prioritizes by exposure (Internet-accessible applications or connected to sensitive environments) and coordinates maintenance windows with business equipment. For individual CVE details and monitoring, see the NVD and the catalogue of exploited vulnerabilities known to CISA: https: / / nvd.nist.gov / vuln / detail / CVE-2026-40138 and https: / / www.cisa.gov / knowledge-exploited-vulnerabilities-catalog.
An additional point of editorial interest is that BeyondTrust attributes part of the finding to internal evaluations assisted by public IA models (e.g. Anthropic Claude Opus 4.8) along with its own tools. This illustrates how the IA accelerates vulnerability research but also raises the need for responsible validation and disclosure processes: automatic discovery accelerates the identification cycle, but organizations must have rigorous controls to avoid false positive and manage coordinated mitigation prior to public disclosure. Technology is accelerating, but governance and operational response remain the key factor in reducing risk.
In short, the immediate recommendation for security managers and equipment is clear: it plans and installs updates to RS / PRA 25.3.3 or higher, applies network and MFA restrictions, makes proactive detection of commitment signs and documents the actions taken. The combination of patches and mitigating operational controls is the best defense while the security community monitors if exploits appear in nature.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...