Drooid Logo
Back to today’s briefing

Story perspectives

Ransomware Threats Surge as CVE-2026-1731 Exploited Globally

2/21/2026

33 7 Full Breakdown

1 of 1

Story summary
  • Threat actors exploit CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access to run commands without user interaction.
  • Palo Alto Networks' Unit 42 reports exploitation across finance and healthcare in the United States and France.
  • The flaw enables SparkRAT and VShell malware deployment.
  • The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-1731 to its Known Exploited Vulnerabilities catalog, signaling ransomware campaigns.
  • Researchers warn threat actors are increasing activity before patches.