PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Network Vulnerabilities·Updated Feb 10, 2026

BeyondTrust Remote Support - Unauthenticated WebSocket RCE

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
2.3k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2026-1731
9.9
CVSScritical
Exploitable remotely over the internet · no authentication required.

BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Remote Support(RS) & Privileged Remote Access(PRA)by BeyondTrust
0
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

BeyondTrust Remote Support - Unauthenticated WebSocket RCE CVE-2026-1731 Scanner | S4E