CVE-2026-1731
CRITICAL KEV RANSOMWARE NUCLEIBeyondTrust RS/PRA - RCE
Title source: llmDescription
BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.
Exploits (10)
github
WORKING POC
10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-1731
metasploit
WORKING POC
EXCELLENT
by Harsh Jaiswal, Jonah Burgess (CryptoCat) · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/beyondtrust_pra_rs_command_injection.rb
Nuclei Templates (1)
BeyondTrust Remote Support - Unauthenticated WebSocket RCE
CRITICALVERIFIEDby attackerkb,hacktron,pdteam
Shodan:
http.html:"BeyondTrust"
References (5)
Scores
CVSS v3
9.8
EPSS
0.8150
EPSS Percentile
99.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2026-02-13
VulnCheck KEV
2026-02-12
ENISA EUVD
EUVD-2026-5559
Ransomware Use
Confirmed
CWE
CWE-78
Status
published
Products (2)
beyondtrust/privileged_remote_access
< 25.1
beyondtrust/remote_support
< 25.3.2
Published
Feb 06, 2026
KEV Added
Feb 13, 2026
Tracked Since
Feb 18, 2026