AI Stories on SHORT INFO are generated & curated with AI
unverified 08 Jul, 19:12

BeyondTrust patches critical CVSS 9.2 authentication bypass flaws CVE-2026-40138 and CVE-2026-40139

Self-hosted BeyondTrust appliances are exposed until admins patch: two CVSS 9.2 pre-auth flaws, CVE-2026-40138 and CVE-2026-40139, let unauthenticated attackers reach privileged accounts in Remote Support and Privileged Remote Access. Cloud was patched in April. Per The Hacker Ne

Organizations running BeyondTrust's Remote Support and Privileged Remote Access on their own infrastructure have urgent patching to do. The vendor has fixed two critical pre-authentication flaws, CVE-2026-40138 and CVE-2026-40139, both rated 9.2 on the CVSS scale. According to the advisories, a network-positioned attacker could bypass access controls without any credentials and gain access to the appliance, including accounts with elevated privileges. Two further vulnerabilities were addressed at the same time: CVE-2026-40140, a pre-authentication issue in the network communication subsystem that can cause denial of service, and CVE-2026-40141, which lets authenticated low-privilege users reach unintended resources. The flaws affect Remote Support and Privileged Remote Access versions 25.3.2 and earlier. The fix is the April 2026 security rollup or an upgrade to version 25.3.3 or later. Cloud-hosted customers were patched automatically on April 21. Self-hosted deployments remain exposed until administrators apply the update themselves, and that is where the residual risk sits: these appliances broker remote access to privileged accounts, so an authentication bypass in front of them is a direct path to the most sensitive credentials an organization has. Exploitation of the two critical flaws depends on a specific authentication configuration being enabled, and BeyondTrust has not reported in-the-wild exploitation. Source: BeyondTrust advisories, reported by The Hacker News and BleepingComputer.

#cyber
Published on
ThreadsFacebookBlueskyX