Story perspectives
Critical BeyondTrust Vulnerability Exploited; Urgent Upgrades Required
2/14/2026
1 of 1
Story summary
- CVE-2026-1731 in BeyondTrust Remote Support is under active exploitation, allowing unauthenticated attackers to execute commands on affected servers.
- Security researchers observed increased reconnaissance activity from a single VPN IP address based in Frankfurt, Germany.
- BeyondTrust has patched cloud versions and requires self-hosted customers to upgrade.
- The U.S. Cybersecurity and Infrastructure Security Agency added the vulnerability to its Known Exploited Vulnerabilities catalog and urges upgrades.
