CVE-2026-40140: BeyondTrust Privileged Remote Access

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the network communication subsystem. Insufficient validation of client-supplied input may allow an unauthenticated remote attacker to trigger a denial-of-service condition affecting appliance availability.

Affected products

  • BeyondTrust Privileged Remote Access: before 25.3.3 (fixed in 25.3.3)
  • BeyondTrust Remote Support: before 25.3.3 (fixed in 25.3.3)

Published 2026-07-06. Last modified 2026-07-07.