Mark RadarMARK RADAR
EN

BeyondTrust Patches Critical Remote-Support Flaws Found With AI Assistance

1 reports · First detected 2026-07-08 · Last active 2026-07-08

BeyondTrust’s Remote Support and Privileged Remote Access (PRA) products are used for enterprise remote support and privileged-account connections. If their authentication mechanisms are compromised, attackers could take control of devices or gain elevated privileges. BeyondTrust’s product security team proactively uncovered the vulnerabilities using publicly available AI models, including Anthropic Claude Opus 4.8, alongside proprietary tools, underscoring AI’s growing role in vulnerability research.

BeyondTrust issued BT26-03 on July 6, 2026, patching CVE-2026-40138 through CVE-2026-40141. The first two flaws each carry a CVSS v4 score of 9.2, while the others are rated 8.7 and 8.5. They could allow unauthorized access, denial of service or unauthorized reading of privileged data. Remote Support and PRA versions 25.3.2 and earlier are affected. Cloud customers were patched on April 21, while on-premises deployments must upgrade to version 25.3.3 or later. BeyondTrust said it had seen no evidence of exploitation.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)