Critical vulnerability in BeyondTrust Remote Support and PRA
BeyondTrust has issued a security advisory (BT26-02) about a critical remote code execution vulnerability affecting its Remote Support and Privileged Remote Access products. The flaw allows an unauthenticated, remote attacker to execute operating system commands, potentially leading to full system compromise, data exfiltration and unauthorised access. Remediation was deployed to all SaaS environments on 2 February 2026, while organisations running the products themselves must verify their update status.
What this means for your organisation
These are privileged remote access tools, meaning systems built to give someone full control of other machines. An unauthenticated attacker with command execution there inherits exactly the access the product exists to govern. For organisations that use such tools to admit suppliers, one vulnerability touches the whole chain of systems those suppliers can reach.
Berigo recommends
- Confirm patch status for self-hosted installations of Remote Support and Privileged Remote Access.
- Review which sessions and accounts were active in the period before the fix became available.
- Restrict which IP addresses can reach the administration interface.
- Review which suppliers hold privileged remote access today and remove the access that is no longer needed.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch