Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Vulnerabilities Fixed in BeyondTrust Support Products

Critical Vulnerabilities Fixed in BeyondTrust Support Products

Posted on July 7, 2026 By CWS

BeyondTrust has addressed two critical security vulnerabilities in its Remote Support (RS) and Privileged Remote Access (PRA) products. These flaws, if left unpatched, could allow unauthorized attackers to seize control of affected devices.

Details of Discovered Vulnerabilities

Each identified flaw could potentially lead to serious security breaches. The vulnerabilities, assigned CVE-2026-40138 and CVE-2026-40139, both received a high CVSS score of 9.2. They result from improper validation and processing of authentication data, enabling attackers to bypass security controls and access privileged accounts without authorization.

Additionally, CVE-2026-40140, with a CVSS score of 8.7, arises from inadequate validation of client inputs, which could trigger a denial-of-service state. Another vulnerability, CVE-2026-40141, with a score of 8.5, involves insufficient input validation that might allow authenticated users to access unauthorized resources.

Conditions for Exploitation

Exploitation of CVE-2026-40138 and CVE-2026-40139 is contingent on specific authentication settings being active. The vulnerability CVE-2026-40141, on the other hand, requires specific user permissions for exploitation.

BeyondTrust discovered these issues internally through rigorous security assessments, utilizing advanced AI tools such as Anthropic Claude Opus 4.8, alongside proprietary research methods. The company emphasizes that unpatched systems may face unauthorized access and potential service disruptions.

Recommended Actions and Updates

To mitigate these risks, BeyondTrust has released patches in RS version 25.3.3 and PRA version 25.3.3. Users operating on versions 25.3.2 or lower are advised to update immediately to protect their systems from potential exploitation.

While there have been no reports of these vulnerabilities being exploited in the wild, similar security issues in the past have led to the deployment of web shells and backdoors. Therefore, timely application of updates is crucial for maintaining system integrity and security.

By addressing these vulnerabilities promptly, BeyondTrust underscores its commitment to maintaining high security standards and protecting its users from potential cyber threats.

The Hacker News Tags:auth bypass, BeyondTrust, Cybersecurity, network security, Patches, Privileged Remote Access, Remote Support, Security, software update, Vulnerabilities

Post navigation

Previous Post: Critical Fast-mcp-telegram Vulnerability Exposed
Next Post: Microsoft Device ID Reveals Scattered Spider Hacker

Related Posts

Ransomware Gangs Use Skitnet Malware for Stealthy Data Theft and Remote Access Ransomware Gangs Use Skitnet Malware for Stealthy Data Theft and Remote Access The Hacker News
Your Digital Footprint Can Lead Right to Your Front Door Your Digital Footprint Can Lead Right to Your Front Door The Hacker News
OceanLotus Targets Vietnamese Firms with SPECTRALVIPER OceanLotus Targets Vietnamese Firms with SPECTRALVIPER The Hacker News
AI Tool Uncovers Critical Redis Security Vulnerability AI Tool Uncovers Critical Redis Security Vulnerability The Hacker News
GhostPoster Malware Found in 17 Firefox Add-ons with 50,000+ Downloads GhostPoster Malware Found in 17 Firefox Add-ons with 50,000+ Downloads The Hacker News
New Linux Flaws Enable Full Root Access via PAM and Udisks Across Major Distributions New Linux Flaws Enable Full Root Access via PAM and Udisks Across Major Distributions The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AppViewX Enhances AI Security with New Tools
  • Cyberattack Exposes Data of Over 1 Million in Arizona Courts
  • Criminal IP Unveils AITEM: Revolutionizing Cybersecurity
  • Iranian Hackers Exploit Fake Coding Test to Infiltrate Iraqi Systems
  • Aembit Enhances Security for AI Agents in Enterprises

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AppViewX Enhances AI Security with New Tools
  • Cyberattack Exposes Data of Over 1 Million in Arizona Courts
  • Criminal IP Unveils AITEM: Revolutionizing Cybersecurity
  • Iranian Hackers Exploit Fake Coding Test to Infiltrate Iraqi Systems
  • Aembit Enhances Security for AI Agents in Enterprises

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark