Remote Support
Vendor:
First CVE: Oct 26, 2017 · Active for 8 years
10
Total CVEs
More Total CVEs than 88% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
8.9
Avg CVSS
Higher Avg CVSS than 83% of tracked products
30.0%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Remote Support over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 26, 2017
8 years ago
Most Recent CVE
Jul 6, 2026
18 days ago
CVE Severity & Scoring
Remote Support10 CVEs
40%
60%
All CVEs352,294 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local1 (10.0%)
Network9 (90.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (90.0%)
High1 (10.0%)
Unknown0 (0.0%)
User Interaction
None9 (90.0%)
Unknown0 (0.0%)
Required1 (10.0%)
Privileges Required
Low1 (10.0%)
High1 (10.0%)
None8 (80.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-1731CRITICAL BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending s | Feb 6, 2026 | 9.8 | 98 | YES | YES |
CVE-2024-12356CRITICAL A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that | Dec 17, 2024 | 9.8 | 98 | YES | YES |
CVE-2024-12686HIGH A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands | Dec 18, 2024 | 7.2 | 70 | YES | NO |
CVE-2026-40139CRITICAL A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauth | Jul 6, 2026 | 9.8 | 46 | NO | NO |
CVE-2026-40141CRITICAL A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters | Jul 6, 2026 | 9.9 | 43 | NO | NO |
CVE-2026-40138HIGH A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication | Jul 6, 2026 | 8.1 | 42 | NO | NO |
CVE-2026-40140HIGH BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the network communication subsystem. Insufficient validation of | Jul 6, 2026 | 7.5 | 37 | NO | NO |
CVE-2025-5309CRITICAL The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code executi | Jun 16, 2025 | 9.8 | 31 | NO | NO |
CVE-2023-4310CRITICAL BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability which can be exploited through a malicious H | Sep 5, 2023 | 9.8 | 30 | NO | NO |
CVE-2017-5996HIGH The agent in Bomgar Remote Support 15.2.x before 15.2.3, 16.1.x before 16.1.5, and 16.2.x before 16.2.4 allows DLL hijacking because of weak %SYSTEMDRIVE%\ProgramData permissions. | Oct 26, 2017 | 7.8 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
3 CVEs
30.0% of CVEs· 98th percentile
Metasploit
2 CVEs
20.0% of CVEs· 97th percentile
Nuclei
2 CVEs
20.0% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Remote Support
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 25.1.1 | 1 | 9.8 | 0.9% | 0 | 0 |
| 23.2.2 | 1 | 9.8 | 1.4% | 0 | 0 |
| 23.2.1 | 1 | 9.8 | 1.4% | 0 | 0 |
| 16.2.2 | 1 | 7.8 | 1.3% | 0 | 0 |
| 16.2.1 | 1 | 7.8 | 1.3% | 0 | 0 |
| 16.1.4 | 1 | 7.8 | 1.3% | 0 | 0 |
| 16.1.3 | 1 | 7.8 | 1.3% | 0 | 0 |
| 16.1.2 | 1 | 7.8 | 1.3% | 0 | 0 |
| 16.1.1 | 1 | 7.8 | 1.3% | 0 | 0 |
| 15.2.2 | 1 | 7.8 | 1.3% | 0 | 0 |
| 15.2.1 | 1 | 7.8 | 1.3% | 0 | 0 |