SecAlerts
BeyondTrust logo

BeyondTrust

Security Risk Profile

75
/100
high

Security Risk Score

Comprehensive risk assessment based on 46 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from October 26, 2017 to present

46
Total CVEs
30
Critical+High
8
Exploited
28
Unpatched

Threat Assessment

Avg CVSS
7.8
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
28
Critical/High
Risk Level
75/100
high
⚠️ 8 Active Exploits 4 Zero-Days📈 5 in Last 30 Days

Severity Distribution

Critical
8
High
22
Medium
6
Low
2

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
9

Age Distribution

Common Weaknesses (CWE)

1
Command Injection
4
2
Infoleak
3
3
OS Command Injection
2
4
SQL Injection
2
5
XSS
2

Most Affected Products

1. BeyondTrust Remote Support29
2. BeyondTrust Privileged Remote Access24
3. BeyondTrust Privilege Management for Windows17
4. IBM Security Guardium6
5. BeyondTrust Beyondinsight Password Safe4

Recent Vulnerabilities

See more →
bleepingcomputer-20260707081210
unknown

BeyondTrust warns of critical flaws in remote access software

7/7/2026🔧 No Patch
CVE-2026-40141
CVSS 8.5high

High-Severity Vulnerability In Web Application Component of BeyondTrust Remote Support and Privileged Remote Access

7/6/2026🔧 No Patch
CVE-2026-40140
CVSS 8.7high

High-Severity Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access

7/6/2026🔧 No Patch
CVE-2026-40139
CVSS 9.2critical

Critical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access

7/6/2026🔧 No Patch
CVE-2026-40138
CVSS 9.2critical

Critical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access

7/6/2026🔧 No Patch
https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-beyondtrust-flaw-within-three-days/
unknown

CISA gives feds 3 days to patch actively exploited BeyondTrust flaw

2/16/2026⚠ Exploited🔧 No Patch
https://reddit.com/r/sysadmin/comments/1r3wb9v/beyondtrust_gets_hit_again_preauth_rce_in_remote/
unknown

BeyondTrust Gets Hit Again: Pre-Auth RCE in Remote Support Tools

2/13/2026🔧 No Patch
https://www.bleepingcomputer.com/news/security/critical-beyondtrust-rce-flaw-now-exploited-in-attacks-patch-now/
unknown

Critical BeyondTrust RCE flaw now exploited in attacks, patch now

2/12/2026⚠ Exploited⚡ Zero-Day🔧 No Patch
https://www.bleepingcomputer.com/news/security/beyondtrust-warns-of-critical-rce-flaw-in-remote-support-software/
unknown

BeyondTrust warns of critical RCE flaw in remote support software

2/9/2026🔧 No Patch
CVE-2026-1731
CVSS 9.9critical

BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability

2/6/2026⚠ Exploited🔧 No Patch

Monitor BeyondTrust in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.