Exploited Known exploited (KEV) Ransomware use CVE-2026-1731

OS command injection in a remote support product (CVE-2026-1731) — no authentication, no user interaction, ransomware use known, and three days to remediate

BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) Added to KEV Feb 13, 2026 Federal remediation due 2026-02-16

BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) contain an OS command injection flaw. With neither authentication nor user interaction required, a remote attacker can execute operating system commands in the context of the site user. CISA added it to the KEV catalog on 2026-02-13 with a due date of 2026-02-16 — three days. Use in ransomware campaigns is recorded as known.

Key facts

  • CVE IDCVE-2026-1731
  • Affected (vendor / product)BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
  • CWECWE-78
  • ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
  • Remediation due2026-02-16 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • The affected products are BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA); CWE-78, OS command injection.
  • Exploitation requires neither authentication nor user interaction, allowing a remote attacker to execute OS commands in the context of the site user.
  • The catalog states it may lead to system compromise including unauthorized access, data exfiltration and service disruption.
  • Added to KEV 2026-02-13 with a due date of 2026-02-16 — three days. Use in ransomware campaigns is recorded as known.
  • Of the 1,685 records this site holds as of 2026-08-31, 352 are ransomware-known; among those, 21 days accounts for 204 while three days appears just 11 times.
  • Among the 352 ransomware-known records, 204 carry 21 days and only 11 carry three — this is one of them.

1The machinery for helping is what gets targeted

Remote support and privileged remote access products exist so that someone can enter another machine or server from elsewhere and work on it. By purpose, being able to get in is the function, and what is entered is often equipment the business depends on. From an attacker view, taking that removes the need to attack machines one at a time.

A tool built for assistance carries the property that the breadth of what it can assist becomes the breadth of what can be harmed.

2Not one precondition required

What makes this record heavy is the express statement that exploitation requires neither authentication nor user interaction. Vulnerabilities this site has covered before have carried preconditions — being authenticated as administrator, having already compromised the renderer. Each precondition raises the difficulty of an attack. Here there is none, so being able to reach comes close to being able to execute.

That the catalog lists unauthorized access, data exfiltration and service disruption together indicates the range of what follows execution.

3Even with ransomware known, only 11 carry three days

Of the 1,685 KEV records this site holds as of 2026-08-31, 352 are recorded as known to be used in ransomware campaigns. Counting the days from listing to due date across those 352, 21 days accounts for 204 — close to six in ten — followed by 181 days at 60 and 14 days at 56. Three days appears just 11 times, and this record is one of them.

Confirmed ransomware use does not automatically shorten the deadline; deadlines are set according to risk under BOD 22-01. A three-day setting is exceptional even within that group.

21 days204 / 352
181 days60 / 352
14 days56 / 352
3 days (this record)11 / 352

Why it matters

Operational support machinery is hard to see in normal times while reaching widely. When it is breached, the effect touches not only the organization that installed it but those receiving support through it. A flaw with no preconditions cannot rely on perimeter defense, so narrowing what can reach it is where the response starts.

FAQ

Why are remote access products targeted?
They exist to let someone enter another machine or server from elsewhere, and what they enter is often equipment the business depends on. The breadth of what they can assist becomes the breadth of what can be harmed.
What does requiring no preconditions mean?
The catalog states expressly that exploitation requires neither authentication nor user interaction. Compared with flaws needing administrator authentication, being able to reach comes close to being able to execute.
Does known ransomware use shorten the deadline?
No. Across the 352 ransomware-known records this site holds as of 2026-08-31, 21 days is most common at 204 and three days appears 11 times. Deadlines are set according to risk under BOD 22-01.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Security#CISA#KEV#Remote access#Ransomware
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.