Story perspectives
Ransomware Threats Surge as CVE-2026-1731 Exploited Globally
2/21/2026
1 of 1
Story summary
- Threat actors exploit CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access to run commands without user interaction.
- Palo Alto Networks' Unit 42 reports exploitation across finance and healthcare in the United States and France.
- The flaw enables SparkRAT and VShell malware deployment.
- The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-1731 to its Known Exploited Vulnerabilities catalog, signaling ransomware campaigns.
- Researchers warn threat actors are increasing activity before patches.
