<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Critical BeyondTrust Flaw Gives Attackers Full Domain Control

Critical CVE-2026-1731 flaw in BeyondTrust systems allows domain takeover. Patch immediately to prevent severe security breaches.
Content Team

Attackers are actively exploiting CVE-2026-1731, a critical vulnerability in BeyondTrust's self-hosted systems that allows complete domain takeover without authentication. The flaw lets hackers execute operating system commands remotely through crafted HTTP requests, earning a devastating 9.8 CVSS score.

Threat actors are deploying SimpleHelp remote access tools and creating privileged domain accounts with Enterprise Admin rights. Arctic Wolf researchers found attackers using reconnaissance commands to map Active Directory networks before spreading across multiple hosts via PSExec and Impacket tools.

Cloud customers received automatic patches on February 2, 2026, but self-hosted users running Remote Support 25.3.1 or Privileged Remote Access 24.3.4 must manually apply updates immediately. CISA warns older versions need upgrades first before patching.

Source: Cybersecurity News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo