BeyondTrust has issued urgent warnings about two critical security vulnerabilities in its Remote Support and Privileged Remote Access software that could allow attackers to bypass authentication mechanisms.
The vulnerabilities affect BeyondTrust's Remote Support (RS) and Privileged Remote Access (PRA) platforms, which are widely used by enterprises for secure remote connectivity and privileged account management.
The flaws could enable attackers to circumvent authentication controls, potentially granting unauthorized access to remote systems and sensitive infrastructure. BeyondTrust has advised all customers to apply patches immediately.
Remote access software represents a critical attack surface in enterprise security. Authentication bypass vulnerabilities in such tools are particularly concerning, as they can provide attackers with direct pathways to internal networks without proper credential verification.
The company has released security updates addressing both vulnerabilities. Customers running affected versions of RS and PRA are urged to prioritize patching as part of their security operations. BeyondTrust has provided detailed technical guidance and patch information through its security advisory channels.
No public information indicates active exploitation of these vulnerabilities in the wild at this time. However, given the critical nature of the flaws and the broad use of BeyondTrust's software across enterprise environments, rapid patching is essential to prevent potential compromise.
Organizations using BeyondTrust's remote access solutions should verify their current software versions against the company's vulnerability bulletins and apply available patches according to their change management procedures. Security teams should also review access logs for any suspicious activity on affected systems.
This incident underscores the ongoing need for vendors and enterprises to maintain rigorous vulnerability management practices. Remote access tools continue to be targets for adversaries seeking entry points into corporate networks.
Mullvad is discontinuing its public encrypted DNS servers and redirecting resources to sponsor Quad9, an alternative privacy-focused DNS provider. The move consolidates the privacy DNS landscape.
The US Department of Defense has implemented a policy to disable advertising trackers on military personnel's mobile devices. The measure aims to prevent location data and personal information from being collected and sold by third-party companies.
Identity verification company IDScan faces multiple lawsuits after hackers allegedly accessed and attempted to sell driver's license data for over 153 million individuals.
Attackers are actively exploiting a critical authentication bypass vulnerability in Citrix NetScaler, according to Previdian. CVE-2026-19490 allows threat actors to circumvent security controls on the widely-deployed application delivery platform.