CVE-2026-1731

BeyondTrust — BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability

CISA KEV · in the CISA KEV catalog since 2026-02-13

What EVULNABLE says

EVULNABLE Risk · priority 94/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data
ExigentOverdue by 7 monthsRansomwareCISA KEVActively Exploited

Why it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.894.

Out-of-Band / Urgent Remediation

The priority band answers “how soon”, not “how bad” — see Methodology for what it weighs and where it abstains.

The evidence behind it

Published measurements for CVE-2026-1731
MeasureValueSource
CVSS base score 9.9 NVD
FIRST EPSS 0.894 (99.77th pctl) FIRST
Actively exploited Confirmed CISA KEV
Ransomware campaign use Known CISA KEV
CISA remediation deadline 2026-02-16 — Overdue by 7 months CISA KEV
Intelligence coverage 75/90 — no pre-patch disclosure data

What CISA says to do

  • Please adhere to the vendor's guidelines to assess exposure and mitigate risks. Check for signs of potential compromise on all internet accessible BeyondTrust products affected by this vulnerability. For more information please: see: https://www.beyondtrust.com/trust-center/security-advisories/bt26-02
  • nvd.nist.gov/…/CVE-2026-1731 ↗

This page is an opinion about urgency. Where it and a source of record disagree, the source of record is the record.