<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — BeyondTrust</title><description>Vulnerabilities and patches across BeyondTrust&apos;s remote-access and privileged-access product line — Remote Support (RS), Privileged Remote Access (PRA), and adjacent PAM appliances whose compromise typically hands attackers a foothold in the vendor-and-third-party access path into an enterprise. Combined article + CVE feed for the BeyondTrust beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>CVE-2024-12356 — BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability </title><link>https://0daynews.com/cve/cve-2024-12356/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-12356/</guid><description>BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection vulnerability, which can allow an unauthenticated attacker to inject commands that are run as a site user. </description><pubDate>Sat, 22 Aug 2026 00:00:00 GMT</pubDate><category>BeyondTrust</category><category>critical</category><category>cve</category></item><item><title>CVE-2024-12686 — BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2024-12686/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-12686/</guid><description>BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection vulnerability that can be exploited by an attacker with existing administrative privileges to upload a malicious file. Successful exploitation of this vulnerability can allow a remote attacker to execute underlying operating system commands within the context of the site user.</description><pubDate>Sat, 22 Aug 2026 00:00:00 GMT</pubDate><category>BeyondTrust</category><category>medium</category><category>cve</category></item><item><title>CVE-2026-1731 — BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2026-1731/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-1731/</guid><description>BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of the site user. Successful exploitation requires no authentication or user interaction and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption.</description><pubDate>Sat, 22 Aug 2026 00:00:00 GMT</pubDate><category>BeyondTrust</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-40138 — BeyondTrust Remote Support / PRA pre-auth authentication bypass</title><link>https://0daynews.com/cve/cve-2026-40138/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-40138/</guid><description>A pre-authentication authentication-bypass flaw in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA). Improper validation of authentication data may let a network-positioned attacker bypass access controls and reach appliance accounts, including elevated ones. Vendor labels the flaw &quot;critical&quot; in its advisory; NVD scores it CVSS 8.1 (high). Patched in the 2026-07-06 coordinated release; exploitation requires a specific authentication configuration to be enabled.</description><pubDate>Sat, 22 Aug 2026 00:00:00 GMT</pubDate><category>BeyondTrust</category><category>high</category><category>cve</category></item><item><title>CVE-2026-40139 — BeyondTrust Remote Support pre-auth authentication bypass (critical)</title><link>https://0daynews.com/cve/cve-2026-40139/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-40139/</guid><description>A critical (CVSS 9.8) pre-authentication authentication-bypass flaw in BeyondTrust Remote Support (RS). Improper processing of authentication requests may let an unauthenticated remote attacker bypass access controls and reach appliance accounts, including elevated ones. Patched in the 2026-07-06 coordinated release; exploitation requires a specific authentication configuration to be enabled.</description><pubDate>Sat, 22 Aug 2026 00:00:00 GMT</pubDate><category>BeyondTrust</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-40140 — BeyondTrust Remote Support / PRA pre-auth denial of service</title><link>https://0daynews.com/cve/cve-2026-40140/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-40140/</guid><description>A high-severity (CVSS 7.5) pre-authentication denial-of-service flaw in BeyondTrust Remote Support and Privileged Remote Access. Insufficient validation of client-supplied input in the network communication subsystem may let an unauthenticated remote attacker trigger a DoS condition against appliance availability. Patched in the 2026-07-06 coordinated release.</description><pubDate>Sat, 22 Aug 2026 00:00:00 GMT</pubDate><category>BeyondTrust</category><category>high</category><category>cve</category></item><item><title>CVE-2026-40141 — BeyondTrust Remote Support / PRA authenticated authorization bypass</title><link>https://0daynews.com/cve/cve-2026-40141/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-40141/</guid><description>A critical (CVSS 9.9) authenticated authorization-bypass flaw in a web-application component of BeyondTrust Remote Support and Privileged Remote Access. Insufficient input validation may let an authenticated attacker with limited privileges reach data or resources beyond their authorization scope. Exploitation is restricted to accounts with specific permissions. Patched in the 2026-07-06 coordinated release.</description><pubDate>Sat, 22 Aug 2026 00:00:00 GMT</pubDate><category>BeyondTrust</category><category>critical</category><category>cve</category></item><item><title>BeyondTrust Patches Four RS/PRA Flaws — Patch Now</title><link>https://0daynews.com/articles/2026-07-07-beyondtrust-remote-support-pra-auth-bypass/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-07-beyondtrust-remote-support-pra-auth-bypass/</guid><description>BeyondTrust shipped fixes on July 6 for four vulnerabilities in Remote Support and Privileged Remote Access, including a CVSS 9.8 pre-auth bypass. No in-wild exploitation reported. Here&apos;s the priority order.</description><pubDate>Tue, 07 Jul 2026 22:15:00 GMT</pubDate><category>BeyondTrust</category><category>article</category></item></channel></rss>