Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Beyondtrust

First CVE: Oct 26, 2017Active for: 9 yearsTotal CVEs: 37
78.7
VTI Score
TOP TARGET

BeyondTrust develops a focused but strategically critical suite of privileged access management and remote support products deployed across enterprise environments, where a single vulnerability can expose authentication and authorization controls at scale. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, an elevated tendency toward confirmed in-the-wild exploitation and CISA KEV cataloging, and frequent public exploit availability. The exposure recurs across its flagship products including Privilege Management for Windows, Privileged Remote Access, and BeyondInsight Password Safe, driven by recurring weakness classes centered on improper authentication, privilege management flaws, sensitive-information disclosure, and input-validation issues endemic to identity and access-control systems. Defenders should prioritize patching this vendor's releases and inventory privileged-access gateways and remote-support deployments as high-value targets; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
37
Total CVEs
More Total CVEs than 98% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
10.8%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Beyondtrust over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 26, 2017
8 years ago
Most Recent CVE
Jul 6, 2026
19 days ago

Products(12 total)

Top CVEs

Signals from CVEs in this vendor scope (37 CVEs).

37 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-3156HIGH
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line arg
Jan 26, 20217.899YESYES
CVE-2026-1731CRITICAL
BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending s
Feb 6, 20269.898YESYES
CVE-2024-12356CRITICAL
A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that
Dec 17, 20249.898YESYES
CVE-2024-12686HIGH
A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands
Dec 18, 20247.270YESNO
CVE-2021-31589MEDIUM
A cross-site scripting (XSS) vulnerability has been reported and confirmed for BeyondTrust Secure Remote Access Base Software version 6.0.1 and older, which allows the injection of
Jan 5, 20226.148NOYES
CVE-2026-40139CRITICAL
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauth
Jul 6, 20269.846NONO
CVE-2026-40141CRITICAL
A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters
Jul 6, 20269.943NONO
CVE-2026-40138HIGH
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication
Jul 6, 20268.142NONO
CVE-2026-40140HIGH
BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the network communication subsystem. Insufficient validation of
Jul 6, 20267.537NONO
CVE-2025-5309CRITICAL
The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code executi
Jun 16, 20259.831NONO
View all 37 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products37 CVEs
19%
57%
19%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local18 (48.6%)
Network19 (51.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low36 (97.3%)
High1 (2.7%)
Unknown0 (0.0%)
User Interaction
None34 (91.9%)
Unknown0 (0.0%)
Required3 (8.1%)
Privileges Required
Low17 (45.9%)
High6 (16.2%)
None14 (37.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (37 CVEs).

CISA KEV
4 CVEs
10.8% of CVEs· 100th percentile
Metasploit
3 CVEs
8.1% of CVEs· 98th percentile
Nuclei
4 CVEs
10.8% of CVEs· 96th percentile
ExploitDB
1 CVE
2.7% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Beyondtrust.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Beyondtrust — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Beyondtrust's Products

View all 3 CNAs →

Top CWEs