BeyondTrust patches critical authentication-bypass flaws in Remote Support and Privileged Remote Access

BeyondTrust warned customers to urgently patch critical flaws in its Remote Support and Privileged Remote Access products that could let attackers get in without proper authentication. The issues include CVE-2026-40138 and CVE-2026-40139, affecting RS and PRA versions 25.3.2 and earlier, and can allow unauthorized access under specific authentication configurations; two additional high-severity flaws, CVE-2026-40140 and CVE-2026-40141, can cause denial of service or expose restricted resources. Cloud customers were patched by April 21, 2026, while self-hosted customers must apply the April security rollup or upgrade to 25.3.3 or later.
Why it matters: Organizations using BeyondTrust for remote administration could be exposed to break-ins that bypass login controls, including access to privileged accounts. This is high priority for defenders because internet-facing management tools are frequent intrusion targets, so self-hosted customers should update immediately and review exposed appliances.

Sources

BeyondTrust warns of critical flaws in remote access software
Sergiu Gatlan 2026.07.07 100% relevant
This article establishes a new tracked story because it centers on a newly disclosed set of BeyondTrust CVEs (CVE-2026-40138 through CVE-2026-40141) and the vendor's patch guidance, not on a previously listed BeyondTrust exploitation event.
← Back to all stories