Threat Intelligence / CVE / CVE-2026-1731

CVE-2026-1731

CISA KEVRansomware
CVSS 9.8 (CRITICAL) · EPSS 79.6% · Published 2026-02-06

BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.

CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

CWE-78

Threats tracking this CVE

References

Full detection coverage & IOCs for threats exploiting CVE-2026-1731 are available via the Threadlinqs MCP server (Purple tier). View plans →

Markdown version · Threadlinqs Intelligence