CVE Tools

BeyondTrust warns of critical flaws in remote access software

BleepingComputerBy Sergiu Gatlan

PatchRemote Support (RS)Privileged Remote Access (PRA)

Our summary

BeyondTrust has disclosed critical issues in its Remote Support (RS) and Privileged Remote Access (PRA) products that could let attackers bypass authentication and reach protected appliances. The company cites CVE-2026-40138 (RS and PRA versions 25.3.2 or earlier) and CVE-2026-40139, where improper handling of RS authentication requests could allow unauthenticated remote attackers to gain unauthorized access.

BeyondTrust also released fixes for CVE-2026-40140 and CVE-2026-40141 affecting unpatched RS and PRA instances, which can lead to denial-of-service or unintended access to restricted resources, making patching urgent.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store