BeyondTrust Patches Critical Remote-Support Flaws Found With AI Assistance
BeyondTrust’s Remote Support and Privileged Remote Access (PRA) products are used for enterprise remote support and privileged-account connections. If their authentication mechanisms are compromised, attackers could take control of devices or gain elevated privileges. BeyondTrust’s product security team proactively uncovered the vulnerabilities using publicly available AI models, including Anthropic Claude Opus 4.8, alongside proprietary tools, underscoring AI’s growing role in vulnerability research.
BeyondTrust issued BT26-03 on July 6, 2026, patching CVE-2026-40138 through CVE-2026-40141. The first two flaws each carry a CVSS v4 score of 9.2, while the others are rated 8.7 and 8.5. They could allow unauthorized access, denial of service or unauthorized reading of privileged data. Remote Support and PRA versions 25.3.2 and earlier are affected. Cloud customers were patched on April 21, while on-premises deployments must upgrade to version 25.3.3 or later. BeyondTrust said it had seen no evidence of exploitation.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.