OS command injection in a remote support product (CVE-2026-1731) — no authentication, no user interaction, ransomware use known, and three days to remediate
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) contain an OS command injection flaw. With neither authentication nor user interaction required, a remote attacker can execute operating system commands in the context of the site user. CISA added it to the KEV catalog on 2026-02-13 with a due date of 2026-02-16 — three days. Use in ransomware campaigns is recorded as known.
Key facts
- CVE IDCVE-2026-1731
- Affected (vendor / product)BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
- CWECWE-78
- ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
- Remediation due2026-02-16 (U.S. federal civilian agencies, BOD 22-01)
Key points
- The affected products are BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA); CWE-78, OS command injection.
- Exploitation requires neither authentication nor user interaction, allowing a remote attacker to execute OS commands in the context of the site user.
- The catalog states it may lead to system compromise including unauthorized access, data exfiltration and service disruption.
- Added to KEV 2026-02-13 with a due date of 2026-02-16 — three days. Use in ransomware campaigns is recorded as known.
- Of the 1,685 records this site holds as of 2026-08-31, 352 are ransomware-known; among those, 21 days accounts for 204 while three days appears just 11 times.
- Among the 352 ransomware-known records, 204 carry 21 days and only 11 carry three — this is one of them.
1The machinery for helping is what gets targeted
Remote support and privileged remote access products exist so that someone can enter another machine or server from elsewhere and work on it. By purpose, being able to get in is the function, and what is entered is often equipment the business depends on. From an attacker view, taking that removes the need to attack machines one at a time.
A tool built for assistance carries the property that the breadth of what it can assist becomes the breadth of what can be harmed.
2Not one precondition required
What makes this record heavy is the express statement that exploitation requires neither authentication nor user interaction. Vulnerabilities this site has covered before have carried preconditions — being authenticated as administrator, having already compromised the renderer. Each precondition raises the difficulty of an attack. Here there is none, so being able to reach comes close to being able to execute.
That the catalog lists unauthorized access, data exfiltration and service disruption together indicates the range of what follows execution.
3Even with ransomware known, only 11 carry three days
Of the 1,685 KEV records this site holds as of 2026-08-31, 352 are recorded as known to be used in ransomware campaigns. Counting the days from listing to due date across those 352, 21 days accounts for 204 — close to six in ten — followed by 181 days at 60 and 14 days at 56. Three days appears just 11 times, and this record is one of them.
Confirmed ransomware use does not automatically shorten the deadline; deadlines are set according to risk under BOD 22-01. A three-day setting is exceptional even within that group.
Why it matters
Operational support machinery is hard to see in normal times while reaching widely. When it is breached, the effect touches not only the organization that installed it but those receiving support through it. A flaw with no preconditions cannot rely on perimeter defense, so narrowing what can reach it is where the response starts.
FAQ
Why are remote access products targeted?
What does requiring no preconditions mean?
Does known ransomware use shorten the deadline?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).