IMAGE CREDITS: COREWIRE / AI ILLUSTRATION

BeyondTrust patches twin 9.2 flaws that bypass authentication entirely

CVE-2026-40138 and CVE-2026-40139, both CVSS 9.2, let unauthenticated attackers take control of BeyondTrust Remote Support and Privileged Remote Access appliances. The privileged-access layer is under sustained attack.

The tools that guard privileged access keep becoming the way in. BeyondTrust has released urgent updates for two critical flaws in its Remote Support and Privileged Remote Access products, CVE-2026-40138 and CVE-2026-40139, both scoring CVSS 9.2 and both exploitable before authentication, as reported by The Hacker News.

Both flaws sit in the authentication subsystem itself: improper validation and processing of authentication data that could let a network-positioned attacker bypass access controls and take over susceptible appliances. In plain terms, the products that exist to control who gets privileged access could be made to hand it out.

Why privileged-access tools are the crown-jewel target

A compromised PAM or remote-support appliance is not one breached system; it is a master key to every system it brokers. That is why this class of enterprise software keeps drawing the most capable attackers, BeyondTrust itself disclosed a breach connected to its remote products in the past, and why this advisory lands in the same fortnight as an actively exploited 10.0 in Adobe ColdFusion. The infrastructure layer of enterprise IT is under sustained pressure this summer.

What to do

Patch Remote Support and Privileged Remote Access to the fixed releases immediately; if patching must wait, restrict network exposure of the appliances to known ranges. Then audit session logs for anomalies, pre-auth flaws deserve the assumption of attempts, not the hope of none.

What to watch

Watch for in-the-wild exploitation reports and a possible CISA KEV listing, which would set federal patching deadlines and usually marks the moment criminal groups industrialize an exploit.

Get the Signal

AI and business tech news, verified by a physician who reads the filings. One email a week, no noise.

Dr. Joseph Joshua

Dr. Joseph Joshua is the founder and editor of Corewire. A medical doctor by training, he brings the evidence-first discipline of clinical medicine to technology journalism: claims get checked against primary sources before they get published. He has produced technology and B2B content for companies across…

View Bio

Keep Reading