Vulnerability threat dossier

CVE-2026-1731

beyondtrustprivileged remote access

BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.

VTP deterministic threat59.9of 100 · CVSS excluded

VTP analyst assessment

BeyondTrust pre-authentication command injection

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence95%
Public exploitation · VTP factKEV

Assessment

Critical pre-authentication OS command injection in BeyondTrust Remote Support and certain older Privileged Remote Access versions. Supplied KEV context and independent ENISA EU KEV evidence establish known global exploitation.

Why it matters

  • Crafted network requests can execute commands as the site user without authentication.
  • CVSS 9.9 indicates severe host and downstream security impact; EPSS 0.89396 is predictive context only.

Evidence

2 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.

Uncertainties

A press-linked zero-day assertion has unknown independence and lacks detailed linkage in the supplied excerpt.

Affected local versions, network exposure, and compromise are unknown.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

Remote Support and older PRA deployments accessible from untrusted networks.

AI baseline history (2)
  1. BASELINE ASSESSED
    BeyondTrust pre-authentication command injectiongpt-5.6-sol · high
  2. BASELINE ASSESSED
    BeyondTrust pre-authentication command injectiongpt-5.6-sol · high
Technical severityCRITICALCVSS 9.9 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.90100th percentile · prediction
Evidence confidence95%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    EPSS is 0.90; this is predictive context, not exploitation evidence.

  3. 03

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

4publications detected
4underlying evidence chains

1 primary sources · 0 dependent secondary reports · 3 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimZERO DAYPUBLICATION REPORTS ZERO DAY
64%claim confidence
UNKNOWNreport:a3245ac22fbdfa682646d4fa3328850e649e7d6f999276e27ad1da895c6cdfd9ACTIVE
Evidence
Source claimACTIVE EXPLOITATIONENISA EU KEV LISTED
95%claim confidence
INDEPENDENTcatalog:enisa-eu-kev:CVE-2026-1731ACTIVE
Evidence
04

Event history

Threat timeline

  1. 16:4226 Aug
    ZERO DAY

    Zero Day

    The Hacker News supplied a deterministically extracted signal; review the linked evidence before escalation.

  2. 18:5516 Jul
    EXPLOIT SOURCE UPDATE

    New exploit-source update

    ProjectDiscovery Nuclei Templates Releases published evidence linked to CVE-2026-1731.

  3. 09:2716 Feb
    EXPLOIT SOURCE UPDATE

    New exploit-source update

    ProjectDiscovery Nuclei Templates Releases published evidence linked to CVE-2026-1731.

  4. 00:0013 Feb
    ACTIVE EXPLOITATION

    ENISA EU KEV entry added

    ENISA EU KEV reports known exploitation. VTP imported this historical entry as source baseline. This is public intelligence, not a VTP sensor observation.

  5. 00:0013 Feb
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

05

Original publications

Source record

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司).&

CVE-2018-13379CVE-2019-10068CVE-2019-19781CVE-2020-5902CVE-2021-26855CVE-2021-44228CVE-2023-22515CVE-2024-24919CVE-2024-8190CVE-2024-8963CVE-2024-9380CVE-2025-31161CVE-2026-1731
Separate evidence group
Original

Nuclei Templates v10.4.6 - Release Notes

New Templates Added: 74 | CVEs Added: 23 | First-time contributions: 6 🔥 Release Highlights 🔥 [ CVE-2026-52815 ] Gogs < 0.14.3 - Unauth Organization Teams Disclosure (@0x_Akoko) [low] 🔥 [ CVE-2026-50229 ] Apache Tomcat - Cross-Site Scripting (@yshahinzadeh, @AmirMSafari ) [medium] 🔥 [ CVE-2026-48611 ] phpBB < 3.3.17 - Auth Bypass ( @aikido , @dhiyaneshdk ) [critical] 🔥 [ CVE-2026-48313 ] ColdFusion - Path Traversal ( @watchtowr , @dhiyaneshdk ) [high] 🔥 [ CVE-2026-48282 ] Adobe ColdFusion - RDS Arbitrary File Write ( @watchtowr , @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [CVE-2026-44381] MISP < 2.5.37 - SQL Injection ( @malcha ) [medium] 🔥 [CVE-2026-28496] FOSSBilling - Server-Side Template Injection ( @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-24207 ] NVIDIA Triton Inference Server <= 26.02 - Auth Bypass ( @VixianSchool ) [critical] 🔥 [ CVE-2026-22778 ] vLLM 0.8.3 - 0.14.0 - Information Disclosure ( @kenlacroix ) [critical] 🔥 [ CVE-2026-13731 ] WPBot <= 8.4.9 - Cross-Site Scripting (@0x_Akoko) [high] (vKEV) 🔥 [ CVE-2026-8386 ] WP Go Maps < 10.0.10 - Unauth Marker Information Disclosure (@0x_Akoko) [medium] 🔥 [ CVE-2026-8383 ] LearnPress < 4.3.7 - Information Disclosure (@0x_Akoko) [medium] 🔥 [ CVE-2026-8037 ] Progress ADC LoadMaster - Command Injection ( @watchtowr , @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-3326 ] XStore Theme < 9.7.3 - SQL Injection ( @VixianSchool ) [high] 🔥 [ CVE-2026-1890 ] LeadConnector < 3.0.22 - Unauth Arbitrary Data Write (@0x_Akoko) [medium] (vKEV) 🔥 [ CVE-2025-29635 ] D-Link DIR-823X set_prohibiting - Command Injection ( @pussycat0x ) [high] (kev) (vKEV) 🔥 What's Changed Bug Fixes Fixed invalid matcher type in CVE-2025-29635 (PR #16506 ). Corrected incorrect delay seconds in the time-based SQL injection check (PR #16469 ). Fixed typo in tags from 'okiko' to 'okiok' (PR #16425 ). Corrected severity and description in concrete5-installer.yaml (PR #16523 ). Updated GitHub Pages takeover detection templates to reflect the new GitHub policy (Issue #10514 ). Fixed checksum generation ordering so it runs after template signing completes (PR #16450 ). Removed duplicate and obsolete templates: Tomcat exposed-panels duplicates (PR #16530 ), mikrotik-routeros-old.yaml (PR #16527 ), and 3dprint-arbitrary-file-upload.yaml (PR #16426 ). Corrected template names and file paths across a set of templates — nuuo-network-login (PR #16547 ), fuji-xerox-internet-service (PR #16546 ), trino-unauth-cluster (PR #16560 ), echo-detect (PR #16559 ), XOOPS installer (PR #16531 ), osticket-installer (PR #16529 ), zoneminder-system-log (PR #16498 ), unauth-opcache-control-panel (PR #16424 ), fortiadc-panel (PR #16525 ), Checkmarx panel (PR #16519 ), Cisco TelePresence MCU / ServiceGrid / ACE 4710 panels (PRs #16522 , #16521 , #16520 ), Avaya Aura System Manager and Communication Manager panels (PRs #16518 , #16517 ), joomla-com-fabrik-lfi (PR #16549 ), CVE-2016-9299 (PR #16548 ), and CVE-2025-47188 (PR #16433 ). False Negatives Fixed regex in CVE-2026-1731 that failed on targets returning company instead of default_company (PR #16545 , Issue #16544 ). Extended the Spring Boot heap dump template to cover additional BBO endpoints, catching instances previously missed (PR #16503 , Issue #11653 ). Added more selectors to dkim-record-detect.yaml to reduce missed records (PR #16535 ). Added additional Keycloak admin panel paths (PR #16495 , Issue #16376 ). Added another Spring Boot Actuator HTTP path (PR #16571 ). False Positives Reduced false positives and improved accuracy in the following templates: CVE-2024-37881 — excluded multiple WordPress endpoints and generic redirects (PRs #16494 , #16504 , Issue #16423 ) CVE-2024-34351 — corrected wrong detection (PR #16500 , Issue #11641 ) Time-based SQL injection detection (PR #16510 ) Casbin MCP Gateway default login (PR #16477 ) dns/caa — now matches only the ANSWER section (PR #16453 ) apache-mod-negotiation-listing.yaml - incorrect severity (Issue #16

CVE-2010-4282CVE-2016-9299CVE-2019-5544CVE-2024-34351CVE-2024-37881CVE-2025-29635CVE-2025-47188CVE-2026-10823CVE-2026-13731CVE-2026-1731CVE-2026-1890CVE-2026-22778CVE-2026-24207CVE-2026-28496CVE-2026-30958CVE-2026-3326CVE-2026-34413CVE-2026-44381CVE-2026-46339CVE-2026-48282CVE-2026-48313CVE-2026-48611CVE-2026-50229CVE-2026-50751CVE-2026-52774CVE-2026-52815CVE-2026-56782CVE-2026-59801CVE-2026-8037CVE-2026-8383CVE-2026-8386
Separate evidence group
Original

Nuclei Templates v10.3.9 – Release Notes

New Templates Added: 182 | CVEs Added: 116 | First-time contributions: 7 🔥 Release Highlights 🔥 [ CVE-2026-25892 ] Adminer 4.6.2 - 5.4.1 Unauthenticated Persistent DoS ( @dhiyaneshdk ) [high] 🔥 [ CVE-2026-23744 ] MCPJam Inspector - Remote Code Execution ( @louay-075 ) [critical] 🔥 [ CVE-2026-22812 ] OpenCode < 1.0.216 - Unauthenticated Remote Code Execution ( @princechaddha ) [high] 🔥 [CVE-2026-21891] ZimaOS - Authentication Bypass ( @dhiyaneshdk ) [critical] 🔥 [ CVE-2026-21877 ] n8n >= 0.123.0 and < 1.121.3 - Remote Code Execution ( @s4e-io ) [critical] 🔥 [ CVE-2026-1731 ] BeyondTrust Remote Support - Unauth WebSocket RCE (@attackerkb, @hacktron , @pdteam ) [critical] (KEV) 🔥 [ CVE-2026-1207 ] Django RasterField - SQL Injection ( @omarkurt ) [high] 🔥 [ CVE-2025-54068 ] Laravel Livewire v3 - Remote Command Execution ( @flame-11 ) [critical] 🔥 [ CVE-2025-40551 ] SolarWinds Web Help Desk < 2026.1 - Unauthenticated JNDI Injection RCE (@Horizon3.ai) [critical] (KEV) 🔥 [ CVE-2025-14528 ] D-Link DIR-803 - Authentication Bypass ( @dhiyaneshdk ) [high] 🔥 [ CVE-2025-2611 ] ICTBroadcast - Command Injection ( @Chocapikk ) [critical] (vKEV) 🔥 [ CVE-2024-8943 ] LatePoint <= 5.0.12 - Authentication Bypass ( @daffainfo ) [critical] (vKEV) 🔥 [ CVE-2024-8911 ] LatePoint <= 5.0.11 - SQL Injection ( @daffainfo ) [critical] (vKEV) 🔥 [ CVE-2024-6671 ] WhatsUp Gold GetStatisticalMonitorList SQLi - Authentication Bypass ( @daffainfo , @jjcho ) [critical] (vKEV) 🔥 [ CVE-2024-6250 ] LOLLMS WebUI - Absolute Path Traversal ( @ritikchaddha ) [high] 🔥 [ CVE-2024-0705 ] Stripe Payment Plugin for WooCommerce <= 3.7.9 - Unauth SQL Injection ( @Shivam Kamboj) [critical] 🔥 [ CVE-2023-35708 ] MOVEit Transfer - SQL Injection ( @daffainfo , @jjcho ) [critical] (vKEV) 🔥 [ CVE-2022-31678 ] VMWare Cloud Foundation NSX-V - XML External Entity (XXE) ( @daffainfo ) [critical] (vKEV) 🔥 [ CVE-2022-3236 ] Sophos Firewall <= 19.0 MR1 - Remote Code Execution ( @daffainfo ) [critical] (KEV) 🔥 [ CVE-2021-22017 ] vCenter Server - Improper Access Control ( @daffainfo ) [medium] (KEV) 🔥 [ CVE-2019-13608 ] Citrix StoreFront Server - XML External Entity ( @daffainfo ) [high] (KEV) 🔥 [ CVE-2017-9841 ] PHPUnit - Remote Code Execution (@Random_Robbie, @pikpikcu ) [critical] (KEV) 🔥 What's Changed Bug Fixes Fixed incorrect tag formatting (- appearing as a tag) in CVE-2019-17444 template (PR #15306 ) Fixed incorrect reference in authentik-panel template (PR #15298 ) Fixed port format in unauth-java-message-broker-detect template (PR #15117 ) Fixed tag formatting (double comma) in templates (PR #15118 ) Fixed formatting of tags in CVE-2019-5591 template (PR #15119 ) Fixed port used on CVE-2014-0160 Heartbleed — was testing port 443 twice instead of testing plain HTTP port (PR #14653 ) Fixed path for gude-default-login template (PR #15134 ) Moved CVE-2024-43283 .yaml to correct directory http/cves/2024 (PR #15100 ) Updated CVE-2025-68645 .yaml (PR #15109 ) Updated CVE-2024-13094 .yaml with new alert script (PR #15299 ) Updated CVE-2021-24527 .yaml (PR #14980 ) False Negatives Fixed false negative in CVE-2025-24963 on Linux targets (Ubuntu/Debian) due to strict /etc/passwd matching (PR #15301 , Issue #15205 ) False Positives Reduced false positives in wp-wps-hide-login-log template that triggered on non-WordPress SPA sites (PR #15096 , Issue #15089 ) Fixed false positives in CVE-2021-35042 matcher — status_code == 500 alone was triggering on generic 500 pages (PR #15250 ) Made matchers for weak-csp-detect more granular to avoid duplicate matching results (PR #15123 ) Improved weak CSP detection logic, fixed matcher conditions and corrected regex typo (PR #15014 ) Enhancements Enhanced Cisco UCM username enumeration template to extract usernames, emails, and phone numbers added 3 new Cisco UCM templates (PR #15049 ) Refactored Open WebUI template to make detection more generic (PR #15251 ) Rewrote templates from RAW HTTP to normal HTTP for clustering support, saving

CVE-2014-0160CVE-2017-9841CVE-2018-16363CVE-2019-13608CVE-2019-17444CVE-2019-5591CVE-2020-37123CVE-2021-22017CVE-2021-24139CVE-2021-24527CVE-2021-24786CVE-2021-35042CVE-2021-41097CVE-2022-28987CVE-2022-29495CVE-2022-31678CVE-2022-3236CVE-2022-3254CVE-2022-45836CVE-2023-24000CVE-2023-28787CVE-2023-3197CVE-2023-35708CVE-2023-44982CVE-2023-45648CVE-2023-5204CVE-2023-6970CVE-2024-0705CVE-2024-10152CVE-2024-11868CVE-2024-12585CVE-2024-12638CVE-2024-12724CVE-2024-12732CVE-2024-12734CVE-2024-12737CVE-2024-12749CVE-2024-12873CVE-2024-12878CVE-2024-13055CVE-2024-13094CVE-2024-13097CVE-2024-13098CVE-2024-13099CVE-2024-13112CVE-2024-13114CVE-2024-13219CVE-2024-13220CVE-2024-13221CVE-2024-13222CVE-2024-13224CVE-2024-13225CVE-2024-13226CVE-2024-13325CVE-2024-13326CVE-2024-13327CVE-2024-13328CVE-2024-13330CVE-2024-13331CVE-2024-13352CVE-2024-13492CVE-2024-13543CVE-2024-13569CVE-2024-13570CVE-2024-13609CVE-2024-13619CVE-2024-13625CVE-2024-13627CVE-2024-13628CVE-2024-13630CVE-2024-13634CVE-2024-13727CVE-2024-14015CVE-2024-1751CVE-2024-30490CVE-2024-32128CVE-2024-3231CVE-2024-3408CVE-2024-3605CVE-2024-37259CVE-2024-43283CVE-2024-5333CVE-2024-5483CVE-2024-6250CVE-2024-6265CVE-2024-6671CVE-2024-8911CVE-2024-8943CVE-2025-10090CVE-2025-10353CVE-2025-11368CVE-2025-1232CVE-2025-1303CVE-2025-13138CVE-2025-1338CVE-2025-13956CVE-2025-14155CVE-2025-14528CVE-2025-15503CVE-2025-22214CVE-2025-24582CVE-2025-24786CVE-2025-24963CVE-2025-2611CVE-2025-28242CVE-2025-32257CVE-2025-40551CVE-2025-4078CVE-2025-4652CVE-2025-54068CVE-2025-66744CVE-2025-68509CVE-2025-68645CVE-2025-8266CVE-2026-0594CVE-2026-1207CVE-2026-1731CVE-2026-21877CVE-2026-21891CVE-2026-22812CVE-2026-23744CVE-2026-24128CVE-2026-25892
Separate evidence group
Original

ENISA EU KEV catalog membership for CVE-2026-1731

ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.

CVE-2026-1731
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score59.9vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction17.9 / 20
Exploit availability2.5 / 15
Source independence7.5 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.9 · CRITICAL
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE
CWE-78
CPE records
2
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.