Affected Systems
BeyondTrust Remote Support and Privileged Remote Access (PRA) products. Specific affected versions not provided in available data. CVE-2026-40138 is a pre-authentication vulnerability with CVSS 9.2.
Exploitation Status
Exploitation status unknown. Patches released by vendor. No information provided on active exploitation or public proof-of-concept availability.
Business Impact
Pre-authentication bypass allows unauthenticated remote attackers to take full control of BeyondTrust Remote Support and PRA appliances without credentials. These products are commonly used for privileged access management and remote support, making compromise a critical risk for lateral movement and credential theft. Organizations using these products face immediate risk of complete device takeover.
Urgency
🔴 Immediate
Recommended Actions
- Identify all BeyondTrust Remote Support and Privileged Remote Access instances in your environment immediately
- Apply vendor-supplied patches for CVE-2026-40138 on emergency basis to all affected systems
- Review authentication logs for BeyondTrust products for suspicious pre-authentication activity or unauthorized access attempts
- Restrict network access to BeyondTrust management interfaces to trusted IP ranges only until patching is complete
- Audit privileged accounts and sessions managed through BeyondTrust for signs of unauthorized access or credential misuse
