BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.
Is CVE-2026-1731 exploited?
Listed in the CISA KEV catalog on 2026-02-13.
Federal remediation due 2026-02-16.
Past that date by 180 days.
Used in ransomware campaigns.
EPSS puts exploitation in the next 30 days at 88%.
Public exploit code: packaged in a public tool.
Public detection rules exist.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
No patch identifier recorded here yet.
What PlainSec published about CVE-2026-1731
PlainSec has not published a story about this CVE.