The tools that guard privileged access keep becoming the way in. BeyondTrust has released urgent updates for two critical flaws in its Remote Support and Privileged Remote Access products, CVE-2026-40138 and CVE-2026-40139, both scoring CVSS 9.2 and both exploitable before authentication, as reported by The Hacker News.
Both flaws sit in the authentication subsystem itself: improper validation and processing of authentication data that could let a network-positioned attacker bypass access controls and take over susceptible appliances. In plain terms, the products that exist to control who gets privileged access could be made to hand it out.
Why privileged-access tools are the crown-jewel target
A compromised PAM or remote-support appliance is not one breached system; it is a master key to every system it brokers. That is why this class of enterprise software keeps drawing the most capable attackers, BeyondTrust itself disclosed a breach connected to its remote products in the past, and why this advisory lands in the same fortnight as an actively exploited 10.0 in Adobe ColdFusion. The infrastructure layer of enterprise IT is under sustained pressure this summer.
What to do
Patch Remote Support and Privileged Remote Access to the fixed releases immediately; if patching must wait, restrict network exposure of the appliances to known ranges. Then audit session logs for anomalies, pre-auth flaws deserve the assumption of attempts, not the hope of none.
What to watch
Watch for in-the-wild exploitation reports and a possible CISA KEV listing, which would set federal patching deadlines and usually marks the moment criminal groups industrialize an exploit.
AI and business tech news, verified by a physician who reads the filings. One email a week, no noise.
