BeyondTrust warns of critical flaws in remote access software
PatchRemote Support (RS)Privileged Remote Access (PRA)Our summary
BeyondTrust has disclosed critical issues in its Remote Support (RS) and Privileged Remote Access (PRA) products that could let attackers bypass authentication and reach protected appliances. The company cites CVE-2026-40138 (RS and PRA versions 25.3.2 or earlier) and CVE-2026-40139, where improper handling of RS authentication requests could allow unauthenticated remote attackers to gain unauthorized access.
BeyondTrust also released fixes for CVE-2026-40140 and CVE-2026-40141 affecting unpatched RS and PRA instances, which can lead to denial-of-service or unintended access to restricted resources, making patching urgent.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.