BeyondTrust warned customers to urgently patch critical flaws in its Remote Support and Privileged Remote Access products that could let attackers get in without proper authentication. The issues include CVE-2026-40138 and CVE-2026-40139, affecting RS and PRA versions 25.3.2 and earlier, and can allow unauthorized access under specific authentication configurations; two additional high-severity flaws, CVE-2026-40140 and CVE-2026-40141, can cause denial of service or expose restricted resources. Cloud customers were patched by April 21, 2026, while self-hosted customers must apply the April security rollup or upgrade to 25.3.3 or later.
Why it matters: Organizations using BeyondTrust for remote administration could be exposed to break-ins that bypass login controls, including access to privileged accounts. This is high priority for defenders because internet-facing management tools are frequent intrusion targets, so self-hosted customers should update immediately and review exposed appliances.
Sergiu Gatlan
2026.07.07
100% relevant
This article establishes a new tracked story because it centers on a newly disclosed set of BeyondTrust CVEs (CVE-2026-40138 through CVE-2026-40141) and the vendor's patch guidance, not on a previously listed BeyondTrust exploitation event.
← Back to all stories