BeyondTrust Inc.
First CVE: Feb 16, 2024Active for: 2 years
21
CVEs Published
More CVEs Published than 41% of tracked CNAs
7.0
Avg CVEs / Year
More Avg CVEs / Year than 42% of tracked CNAs
7.4
Avg CVSS Score
Higher Avg CVSS Score than 64% of tracked CNAs
14.3%
In CISA KEV
Higher KEV Rate than 99% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by BeyondTrust Inc. as a CNA, 0.0% affect products that BeyondTrust Inc. develops as a vendor.
100.0%
Self-reported: 0Third-party: 21
Of all the CVEs published that affect products developed by BeyondTrust Inc., 0.0% are self-published by BeyondTrust Inc. as a CNA.
100.0%
Self-published: 0Published by other CNAs: 8
Trends Over Time
The number and severity of CVEs published by BeyondTrust Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 16, 2024
2 years ago
Most Recent CVE
Jul 6, 2026
18 days ago
Top CVEs
All CVEs published by BeyondTrust Inc. as a CNA, regardless of affected vendor or product.
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-1731CRITICAL BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending s | Feb 6, 2026 | 9.8 | 98 | YES | YES |
CVE-2024-12356CRITICAL A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that | Dec 17, 2024 | 9.8 | 98 | YES | YES |
CVE-2024-12686HIGH A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands | Dec 18, 2024 | 7.2 | 70 | YES | NO |
CVE-2026-40139CRITICAL A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauth | Jul 6, 2026 | 9.8 | 46 | NO | NO |
CVE-2026-40141CRITICAL A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters | Jul 6, 2026 | 9.9 | 43 | NO | NO |
CVE-2026-40138HIGH A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication | Jul 6, 2026 | 8.1 | 42 | NO | NO |
CVE-2026-40140HIGH BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the network communication subsystem. Insufficient validation of | Jul 6, 2026 | 7.5 | 37 | NO | NO |
CVE-2025-5309CRITICAL The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code executi | Jun 16, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-2297HIGH Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certai | Jul 28, 2025 | 7.8 | 27 | NO | NO |
CVE-2025-0217HIGH BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A local authenticated attacker can view the connection details of | May 5, 2025 | 7.8 | 24 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA21 CVEs
10%
24%
38%
29%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local8 (38.1%)
Network13 (61.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (95.2%)
High1 (4.8%)
Unknown0 (0.0%)
User Interaction
None20 (95.2%)
Unknown0 (0.0%)
Required1 (4.8%)
Privileges Required
Low7 (33.3%)
High5 (23.8%)
None9 (42.9%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (21 CVEs).
CISA KEV
3 CVEs
14.3% of CVEs· 99th percentile
Metasploit
2 CVEs
9.5% of CVEs· 98th percentile
Nuclei
2 CVEs
9.5% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by BeyondTrust Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by BeyondTrust Inc. as a CNA — matched by CVE ID, not by organization name.