CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 501

As cited

Copy frozen at (site build).

vulnerabilities

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

BeyondTrust released patches for two critical authentication bypass vulnerabilities in its Remote Support and Privileged Remote Access products that could allow unauthenticated attackers to compromise affected devices. The flaws, including CVE-2026-40138 with a CVSS score of 9.2, require immediate patching to prevent unauthorized access and device takeover.

Why it matters: Organizations running BeyondTrust Remote Support or Privileged Remote Access need to apply these patches immediately, as unauthenticated remote attackers can exploit these flaws to gain full device control without credentials.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

BeyondTrust released patches for two critical authentication bypass vulnerabilities in its Remote Support and Privileged Remote Access products that could allow unauthenticated attackers to compromise affected devices. The flaws, including CVE-2026-40138 with a CVSS score of 9.2, require immediate patching to prevent unauthorized access and device takeover.

Why it matters: Organizations running BeyondTrust Remote Support or Privileged Remote Access need to apply these patches immediately, as unauthenticated remote attackers can exploit these flaws to gain full device control without credentials.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary