Security News

Cybersecurity news aggregator

CRITICAL Vulnerabilities SC Media

BeyondTrust warns of critical flaws in remote access software

BeyondTrust has disclosed two critical authentication bypass vulnerabilities, CVE-2026-40138 (CVSS 8.1) and CVE-2026-40139 (CVSS 9.8), in its Remote Support and Privileged Remote Access software, allowing unauthenticated attackers to gain unauthorized system access. These flaws affect all versions prior to 25.3.3, which contains the necessary patches. With nearly 2,000 instances still exposed online and a history of these tools being exploited for ransomware and espionage, immediate patching to version 25.3.3 is critical.
Read Full Article →

Vulnerability Management BeyondTrust warns of critical flaws in remote access software July 9, 2026 Share By SC Staff (Credit: monticellllo – stock.adobe.com) BeyondTrust has issued a warning to its customers regarding two critical security vulnerabilities in its Remote Support (RS) and Privileged Remote Access (PRA) software that could allow attackers to bypass authentication. These flaws, if exploited, could grant unauthorized access to sensitive systems and data, with further coverage provided by Bleeping Computer. The vulnerabilities, tracked as CVE-2026-40138 and CVE-2026-40139, affect specific versions of BeyondTrust's RS and PRA software. CVE-2026-40138 allows unprivileged attackers to bypass access controls and access appliances, including privileged accounts, due to an improper authentication weakness. CVE-2026-40139 enables unauthenticated remote attackers to gain unauthorized access by improperly processing authentication requests. Both require specific authentication configurations to be exploited. BeyondTrust has also addressed two high-severity issues (CVE-2026-40140 and CVE-2026-40141) that could lead to denial-of-service or access to restricted resources. While BeyondTrust has released patches, nearly 2,000 instances of the software remain exposed online, according to Shadowserver. Past exploitation of BeyondTrust software has been linked to ransomware deployment and state-sponsored espionage campaigns targeting U.S. government agencies. Source: Bleeping Computer SC Staff Related Vulnerability Management Microsoft releases patch for Defender zero-day vulnerability RoguePlanet SC Staff July 9, 2026 The vulnerability, tracked as CVE-2026-50656, was revealed by a security researcher using the handle "Nightmare Eclipse." Vulnerability Management CISA adds ColdFusion, Langflow, and Joomla bugs to known exploited vulnerabilities list Steve Zurier July 8, 2026 Three of the four flaws added to CISA's KEV list were critical. Vulnerability Management ‘Bad Epoll’ vulnerability allows root access on Linux and Android SC Staff July 6, 2026 The Bad Epoll flaw resides within the epoll subsystem of the Linux kernel, a fundamental component for managing network connections and file events. Related Events Cybercast Why Mythos is the cybersecurity crisis we need Wed Jul 22 Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds

Share this article