NCSC-2026-0223 [1.00] [M/H] Vulnerabilities fixed in BeyondTrust Remote Support and Privileged Remote Access
BeyondTrust has fixed vulnerabilities in the products Remote Support and Privileged Remote Access. The vulnerabilities affect multiple aspects of the products Remote Support and Privileged Remote Access. There is a pre-authentication vulnerability that allows a network-based attacker to bypass access controls without prior authentication, provided a specific authentication configuration is enabled. This allows an attacker to gain unauthorized and potentially elevated access. Additionally, there is an issue with insufficient validation of client input in the network communication subsystem, allowing an unauthenticated attacker to cause a denial-of-service by disrupting normal network communication. Furthermore, authenticated users with limited rights can gain access to unauthorized resources due to insufficient input validation, although this is limited to accounts with specific permissions.
CSIRTS triage
- What
- Vulnerabilities allow unauthorized access and Denial of Service due to insufficient validation.
- Who is affected
- Deployments of BeyondTrust Remote Support and Privileged Remote Access are affected.
- Urgency
- Remediation is important due to the potential for unauthorized access and service disruption.
- Action
- Update to the latest version of BeyondTrust products to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Remote Support and Privileged Remote Access
Get an email when a new Remote Support and Privileged Remote Access advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0223
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-401400.57% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-401410.49% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-401380.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-401390.67% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 49% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-40140 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-40141 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-40138 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-40139 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] BeyondTrust Privileged Remote Access and Remote Support: Multiple vulnerabilitiescert-bund
- unknownBeyondTrust Products Multiple Vulnerabilitieshkcert
- criticalCVE-2026-40141: A high-severity vulnerability exists in a web application component of BeyondTrust Remote Supp…nvd
- highCVE-2026-40140: BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentica…nvd
- criticalCVE-2026-40139: A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTr…nvd
- highCVE-2026-40138: A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTr…nvd
Recent advisories for BeyondTrust Remote Support
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] BeyondTrust Privileged Remote Access and Remote Support: Multiple vulnerabilitiescert-bund · 2026-07-08
- criticalCVE-2026-40141: A high-severity vulnerability exists in a web application component of BeyondTrust Remote Supp…nvd · 2026-07-06
- highCVE-2026-40140: BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentica…nvd · 2026-07-06
- criticalCVE-2026-40139: A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTr…nvd · 2026-07-06
- highCVE-2026-40138: A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTr…nvd · 2026-07-06
- criticalexploitedCVE-2026-1731: BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnera…cisa-kev · 2026-02-13
More from NCSC-NL Advisories
- unknownNCSC-2026-0303 [1.01] [M/H] Vulnerabilities patched in GitLab by GitLab Inc.2026-08-25
- unknownNCSC-2026-0326 [1.00] [M/H] Vulnerabilities patched in Keycloak2026-08-25
- unknownNCSC-2026-0325 [1.00] [M/H] Vulnerabilities patched in Atlassian products2026-08-24
- unknownNCSC-2026-0324 [1.00] [M/H] Vulnerability fixed in Zimbra Collaboration Suite2026-08-23
- unknownNCSC-2026-0323 [1.00] [M/H] Vulnerabilities fixed in Cisco Secure Workload2026-08-21