Executive Summary
In July 2026, BeyondTrust disclosed critical vulnerabilities in its Remote Support (RS) and Privileged Remote Access (PRA) software, notably CVE-2026-40138 and CVE-2026-40139. These flaws, stemming from improper authentication handling, could allow unauthenticated attackers to bypass access controls and gain elevated privileges. Exploitation requires specific authentication configurations to be enabled. BeyondTrust has released patches to address these issues.
The disclosure underscores the persistent risks associated with remote access solutions, especially as organizations increasingly rely on them for remote work. Ensuring timely application of security patches and reviewing authentication configurations are crucial to mitigate potential exploitation.
Why This Matters Now
The vulnerabilities in BeyondTrust's remote access software highlight the critical need for organizations to promptly apply security patches and review authentication configurations to prevent unauthorized access and potential data breaches.
Attack Path Analysis
Attackers exploited authentication bypass vulnerabilities in BeyondTrust's Remote Support and Privileged Remote Access software to gain unauthorized access. They escalated privileges by accessing accounts with elevated permissions. Subsequently, they moved laterally within the network to compromise additional systems. Command and control channels were established to maintain persistent access. Sensitive data was exfiltrated from the compromised systems. The attack culminated in significant operational disruption and potential data loss.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited authentication bypass vulnerabilities (CVE-2026-40138 and CVE-2026-40139) in BeyondTrust's Remote Support and Privileged Remote Access software to gain unauthorized access.
Related CVEs
CVE-2026-40138
CVSS 8.1A critical pre-authentication vulnerability in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access allows a network-positioned attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges.
Affected Products:
BeyondTrust Remote Support – < 25.3.3
BeyondTrust Privileged Remote Access – < 25.3.3
Exploit Status:
no public exploitCVE-2026-40139
CVSS 9.8A critical pre-authentication vulnerability in the authentication subsystem of BeyondTrust Remote Support allows an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges.
Affected Products:
BeyondTrust Remote Support – < 25.3.3
Exploit Status:
no public exploitCVE-2026-40140
CVSS 7.5A high-severity pre-authentication vulnerability in the network communication subsystem of BeyondTrust Remote Support and Privileged Remote Access may allow an unauthenticated remote attacker to trigger a denial-of-service condition affecting appliance availability.
Affected Products:
BeyondTrust Remote Support – < 25.3.3
BeyondTrust Privileged Remote Access – < 25.3.3
Exploit Status:
no public exploitCVE-2026-40141
CVSS 9.9A high-severity vulnerability in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters may allow an authenticated attacker with limited privileges to access unintended resources or data beyond their authorization scope.
Affected Products:
BeyondTrust Remote Support – < 25.3.3
BeyondTrust Privileged Remote Access – < 25.3.3
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Valid Accounts
External Remote Services
Exploitation of Remote Services
Application Layer Protocol
Impair Defenses
Cloud Accounts
Modify Authentication Process
Default Accounts
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Authentication for Users and Administrators
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – ICT Risk Management Framework
Control ID: Article 6
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
CISA Zero Trust Maturity Model 2.0 – Identity Governance
Control ID: Identity Pillar
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer/Network Security
Critical authentication bypass flaws in BeyondTrust remote access software directly compromise cybersecurity vendors' privileged access management and remote support infrastructure capabilities.
Government Administration
Authentication bypass vulnerabilities enable unauthorized access to government networks, as demonstrated by Treasury Department breach via BeyondTrust exploitation by state-backed attackers.
Financial Services
Remote access authentication flaws expose financial institutions to privilege escalation attacks, compromising sensitive data and regulatory compliance requirements including PCI-DSS standards.
Information Technology/IT
Authentication bypass in remote support platforms threatens IT service providers' client access management, enabling lateral movement and potential ransomware deployment across managed environments.
Sources
- BeyondTrust warns of critical flaws in remote access softwarehttps://www.bleepingcomputer.com/news/security/beyondtrust-warns-of-critical-flaws-in-remote-access-software/Verified
- BT26-03 | BeyondTrusthttps://www.beyondtrust.com/trust-center/security-advisories/bt26-03Verified
- NVD - CVE-2026-40138https://nvd.nist.gov/vuln/detail/CVE-2026-40138Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely have constrained the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's initial access would likely have been constrained by enforcing strict identity-based access controls, reducing unauthorized entry points.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges would likely have been constrained by enforcing strict segmentation policies, limiting access to sensitive accounts.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement would likely have been constrained by enforcing east-west traffic controls, reducing the ability to access other systems.
Control: Multicloud Visibility & Control
Mitigation: The establishment of command and control channels would likely have been constrained by providing comprehensive visibility and control over network traffic.
Control: Egress Security & Policy Enforcement
Mitigation: The exfiltration of sensitive data would likely have been constrained by enforcing strict egress policies, limiting unauthorized data transfers.
The overall impact of the attack would likely have been constrained by reducing the attacker's ability to move laterally and exfiltrate data.
Impact at a Glance
Affected Business Functions
- Remote Support Services
- Privileged Access Management
Estimated downtime: 3 days
Estimated loss: $50,000
Potential unauthorized access to sensitive client data and administrative credentials.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict access and limit lateral movement.
- • Deploy East-West Traffic Security to monitor and control internal network communications.
- • Utilize Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.
- • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to suspicious activities.
- • Regularly update and patch systems to mitigate known vulnerabilities.



