Beyondtrust
Beyondtrust Remote Support: vulnerabilidades y CVE
Beyondtrust Remote Support tiene 10 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 5 son críticas y 3 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses5
Críticas5
Explotadas activamente3
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-1731 | Crítica (9.9) | 91% | ⚠ Explotación activa | 6 feb 2026 | BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an… |
| CVE-2024-12686 | Alta (7.2) | 14% | ⚠ Explotación activa | 18 dic 2024 | A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user. |
| CVE-2024-12356 | Crítica (9.8) | 87% | ⚠ Explotación activa | 17 dic 2024 | A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-40141 | Alta (8.5) | 0.53% | — | 6 jul 2026 | A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of… |
| CVE-2026-40140 | Alta (8.7) | 0.65% | — | 6 jul 2026 | BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the network communication subsystem. Insufficient validation of client-supplied input may allow an… |
| CVE-2026-40139 | Crítica (9.2) | 0.75% | — | 6 jul 2026 | A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass… |
| CVE-2026-40138 | Crítica (9.2) | 0.46% | — | 6 jul 2026 | A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication data may allow a network-positioned… |
| CVE-2026-1731 | Crítica (9.9) | 91% | ⚠ Explotación activa | 6 feb 2026 | BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an… |
| CVE-2025-5309 | Alta (8.6) | 0.95% | — | 16 jun 2025 | The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code execution. |
| CVE-2024-12686 | Alta (7.2) | 14% | ⚠ Explotación activa | 18 dic 2024 | A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user. |
| CVE-2024-12356 | Crítica (9.8) | 87% | ⚠ Explotación activa | 17 dic 2024 | A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user. |
| CVE-2023-4310 | Crítica (9.8) | 1.8% | — | 5 sept 2023 | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability which can be exploited through a malicious HTTP request. Successful exploitation of… |
| CVE-2017-5996 | Alta (7.8) | 1.3% | — | 26 oct 2017 | The agent in Bomgar Remote Support 15.2.x before 15.2.3, 16.1.x before 16.1.5, and 16.2.x before 16.2.4 allows DLL hijacking because of weak %SYSTEMDRIVE%\ProgramData permissions. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Beyondtrust
Privilege Management FOR Windows · 13Privileged Remote Access · 11Beyondinsight Password Safe · 2U-series Appliance · 2Beyondinsight · 2Privilege Management FOR MAC · 2Appliance Base Software · 1Privilege Management FOR Unix/linux · 1Beyondtrust Provider · 1Privilege Management FOR Windows AND MAC · 1Privileged Identity · 1Avecto Defendpoint · 1