BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.
Is CVE-2026-1731 exploited?
Listed in the CISA KEV catalog on 2026-02-13.
Federal remediation due 2026-02-16.
Past that date by 226 days.
Used in ransomware campaigns.
EPSS puts exploitation in the next 30 days at 91%.