BeyondTrust develops a focused but strategically critical suite of privileged access management and remote support products deployed across enterprise environments, where a single vulnerability can expose authentication and authorization controls at scale. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, an elevated tendency toward confirmed in-the-wild exploitation and CISA KEV cataloging, and frequent public exploit availability. The exposure recurs across its flagship products including Privilege Management for Windows, Privileged Remote Access, and BeyondInsight Password Safe, driven by recurring weakness classes centered on improper authentication, privilege management flaws, sensitive-information disclosure, and input-validation issues endemic to identity and access-control systems. Defenders should prioritize patching this vendor's releases and inventory privileged-access gateways and remote-support deployments as high-value targets; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Beyondtrust over time
Signals from CVEs in this vendor scope (37 CVEs).
37 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3156HIGH Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line arg | Jan 26, 2021 | 7.8 | 99 | YES | YES |
CVE-2026-1731CRITICAL BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending s | Feb 6, 2026 | 9.8 | 98 | YES | YES |
CVE-2024-12356CRITICAL A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that | Dec 17, 2024 | 9.8 | 98 | YES | YES |
CVE-2024-12686HIGH A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands | Dec 18, 2024 | 7.2 | 70 | YES | NO |
CVE-2021-31589MEDIUM A cross-site scripting (XSS) vulnerability has been reported and confirmed for BeyondTrust Secure Remote Access Base Software version 6.0.1 and older, which allows the injection of | Jan 5, 2022 | 6.1 | 48 | NO | YES |
CVE-2026-40139CRITICAL A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauth | Jul 6, 2026 | 9.8 | 46 | NO | NO |
CVE-2026-40141CRITICAL A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters | Jul 6, 2026 | 9.9 | 43 | NO | NO |
CVE-2026-40138HIGH A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication | Jul 6, 2026 | 8.1 | 42 | NO | NO |
CVE-2026-40140HIGH BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the network communication subsystem. Insufficient validation of | Jul 6, 2026 | 7.5 | 37 | NO | NO |
CVE-2025-5309CRITICAL The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code executi | Jun 16, 2025 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (37 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Beyondtrust.
Media articles that mention a CVE ID that affects a product developed by Beyondtrust — matched by CVE ID, not by vendor name.