BeyondTrust records
36 published records for vendor beyondtrust.
Researcher profile
- Entered KEV
- 4 · 11.1%
- Weaponized
- 4 · 11.1%
- Pre-auth RCE
- 4
- With a fix record
- 11.1%
- Median publish → KEV
- 17 days
Recurring classes
- CWE-287 Improper Authentication4
- CWE-269 Improper Privilege Management3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
- CWE-268 Privilege Chaining2
The weakness classes this vendor ships most often: where to look.
CWEAll records
36 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
96Now | CVE-2026-1731Weaponized | Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)beyondtrust · privileged remote access · CWE-78 | Critical9.9 | KEV | 91.0% | Feb 6, 2026 |
95Now | CVE-2024-12356Weaponized | Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA)beyondtrust · privileged remote access · CWE-77 | Critical9.8 | KEV | 87.3% | Dec 17, 2024 |
91Now | CVE-2021-3156Weaponized | Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root sudo project · sudo · CWE-193 | High7.8 | KEV | 100.0% | Jan 26, 2021 |
62This week | CVE-2024-12686Weaponized | Command Injection vulnerability in Remote Support(RS) & Privilege Remote Access (PRA)beyondtrust · privileged remote access · CWE-78 | High7.2 | KEV | 13.7% | Dec 18, 2024 |
40Plan | CVE-2023-4310No exploit | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability whicbeyondtrust · privileged remote access · CWE-77 | Critical9.8 | — | 1.9% | Sep 5, 2023 |
36Monitor | CVE-2026-40139No exploit | Critical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Accessbeyondtrust · privileged remote access · CWE-287 | Critical9.2 | — | 0.8% | Jul 6, 2026 |
36Monitor | CVE-2026-40138No exploit | Critical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Accessbeyondtrust · privileged remote access · CWE-287 | Critical9.2 | — | 0.5% | Jul 6, 2026 |
36Monitor | CVE-2024-4219No exploit | SSRF In BeyondInsightbeyondtrust · beyondinsight · CWE-918 | Critical9.1 | — | 0.2% | Jun 4, 2024 |
35Monitor | CVE-2020-12613No exploit | An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6.beyondtrust · privilege management for windows | High8.8 | — | 0.8% | Dec 11, 2023 |
35Monitor | CVE-2021-3187No exploit | An issue was discovered in BeyondTrust Privilege Management for Mac before 5.7.beyondtrust · privilege management for mac · CWE-276 | High8.8 | — | 0.6% | Dec 11, 2023 |
34Monitor | CVE-2025-5309No exploit | Remote Support & Privileged Remote Access server side template injectionbeyondtrust · privileged remote access · CWE-94 | High8.6 | — | 0.9% | Jun 16, 2025 |
34Monitor | CVE-2026-40140No exploit | High-Severity Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Accessbeyondtrust · privileged remote access · CWE-400 | High8.7 | — | 0.6% | Jul 6, 2026 |
34Monitor | CVE-2026-40141No exploit | High-Severity Vulnerability In Web Application Component of BeyondTrust Remote Support and Privileged Remote Accessbeyondtrust · privileged remote access · CWE-943 | High8.5 | — | 0.5% | Jul 6, 2026 |
32Monitor | CVE-2021-31589Proof of concept | A cross-site scripting (XSS) vulnerability has been reported and confirmed for BeyondTrust Secure Remote Access Base Software version 6.0.1 beyondtrust · appliance base software · CWE-79 | Medium6.1 | — | 25.1% | Jan 5, 2022 |
31Monitor | CVE-2017-5996No exploit | The agent in Bomgar Remote Support 15.2.x before 15.2.3, 16.1.x before 16.1.5, and 16.2.x before 16.2.4 allows DLL hijacking because of weakbeyondtrust · remote support · CWE-426 | High7.8 | — | 1.3% | Oct 26, 2017 |
31Monitor | CVE-2021-42254No exploit | BeyondTrust Privilege Management prior to version 21.6 creates a Temporary File in a Directory with Insecure Permissions.beyondtrust · privilege management for windows · CWE-668 | High7.8 | — | 0.3% | Nov 19, 2021 |
31Monitor | CVE-2020-12612No exploit | An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6.beyondtrust · privilege management for windows | High7.8 | — | 0.3% | Dec 12, 2023 |
31Monitor | CVE-2020-28369No exploit | In BeyondTrust Privilege Management for Windows (aka PMfW) through 5.7, a SYSTEM installation causes Cryptbase.dll to be loaded from the usebeyondtrust · privilege management for windows · CWE-427 | High7.8 | — | 0.2% | Dec 12, 2023 |
31Monitor | CVE-2020-12615No exploit | An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6.beyondtrust · privilege management for windows · CWE-269 | High7.8 | — | 0.2% | Dec 12, 2023 |
31Monitor | CVE-2023-23632No exploit | BeyondTrust Privileged Remote Access (PRA) versions 22.2.x to 22.4.x are vulnerable to a local authentication bypass.beyondtrust · privileged remote access · CWE-287 | High7.8 | — | 0.2% | Oct 12, 2023 |
31Monitor | CVE-2024-4017No exploit | Privilege Escalation in U-Series Appliancebeyondtrust · u-series appliance · CWE-269 | High7.8 | — | 0.2% | Apr 19, 2024 |
31Monitor | CVE-2024-4018No exploit | Privilege Escalation in U-Series Appliancebeyondtrust · u-series appliance · CWE-269 | High7.8 | — | 0.2% | Apr 19, 2024 |
31Monitor | CVE-2020-12614No exploit | An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6.beyondtrust · privilege management for windows · CWE-295 | High7.8 | — | 0.1% | Dec 12, 2023 |
31Monitor | CVE-2024-25083No exploit | An issue was discovered in BeyondTrust Privilege Management for Windows before 24.1.beyondtrust · privilege management for windows · CWE-266 | High7.8 | — | 0.1% | Feb 16, 2024 |
30Monitor | CVE-2018-10959No exploit | Avecto Defendpoint 4 prior to 4.4 SR6 and 5 prior to 5.1 SR1 has an Untrusted Search Path vulnerability, exploitable by modifying environmenbeyondtrust · avecto defendpoint · CWE-426 | High7.5 | — | 1.6% | Apr 17, 2019 |
- CVE-2026-173196Now
Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
CriticalCVSS 9.9KEVWeaponizedEPSS 91%beyondtrust · privileged remote accessFeb 6, 2026
- CVE-2024-1235695Now
Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA)
CriticalCVSS 9.8KEVWeaponizedEPSS 87%beyondtrust · privileged remote accessDec 17, 2024
- CVE-2021-315691Now
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root
HighCVSS 7.8KEVWeaponizedEPSS 100%sudo project · sudoJan 26, 2021
- CVE-2024-1268662This week
Command Injection vulnerability in Remote Support(RS) & Privilege Remote Access (PRA)
HighCVSS 7.2KEVWeaponizedEPSS 14%beyondtrust · privileged remote accessDec 18, 2024
- CVE-2023-431040Plan
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability whic
CriticalCVSS 9.8No exploitEPSS 2%beyondtrust · privileged remote accessSep 5, 2023
- CVE-2026-4013936Monitor
Critical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access
CriticalCVSS 9.2No exploitEPSS 1%beyondtrust · privileged remote accessJul 6, 2026
- CVE-2026-4013836Monitor
Critical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access
CriticalCVSS 9.2No exploitEPSS 0%beyondtrust · privileged remote accessJul 6, 2026
- CVE-2024-421936Monitor
SSRF In BeyondInsight
CriticalCVSS 9.1No exploitEPSS 0%beyondtrust · beyondinsightJun 4, 2024
- CVE-2020-1261335Monitor
An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6.
HighCVSS 8.8No exploitEPSS 1%beyondtrust · privilege management for windowsDec 11, 2023
- CVE-2021-318735Monitor
An issue was discovered in BeyondTrust Privilege Management for Mac before 5.7.
HighCVSS 8.8No exploitEPSS 1%beyondtrust · privilege management for macDec 11, 2023
- CVE-2025-530934Monitor
Remote Support & Privileged Remote Access server side template injection
HighCVSS 8.6No exploitEPSS 1%beyondtrust · privileged remote accessJun 16, 2025
- CVE-2026-4014034Monitor
High-Severity Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access
HighCVSS 8.7No exploitEPSS 1%beyondtrust · privileged remote accessJul 6, 2026
- CVE-2026-4014134Monitor
High-Severity Vulnerability In Web Application Component of BeyondTrust Remote Support and Privileged Remote Access
HighCVSS 8.5No exploitEPSS 1%beyondtrust · privileged remote accessJul 6, 2026
- CVE-2021-3158932Monitor
A cross-site scripting (XSS) vulnerability has been reported and confirmed for BeyondTrust Secure Remote Access Base Software version 6.0.1
MediumCVSS 6.1Proof of conceptEPSS 25%beyondtrust · appliance base softwareJan 5, 2022
- CVE-2017-599631Monitor
The agent in Bomgar Remote Support 15.2.x before 15.2.3, 16.1.x before 16.1.5, and 16.2.x before 16.2.4 allows DLL hijacking because of weak
HighCVSS 7.8No exploitEPSS 1%beyondtrust · remote supportOct 26, 2017
- CVE-2021-4225431Monitor
BeyondTrust Privilege Management prior to version 21.6 creates a Temporary File in a Directory with Insecure Permissions.
HighCVSS 7.8No exploitEPSS 0%beyondtrust · privilege management for windowsNov 19, 2021
- CVE-2020-1261231Monitor
An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6.
HighCVSS 7.8No exploitEPSS 0%beyondtrust · privilege management for windowsDec 12, 2023
- CVE-2020-2836931Monitor
In BeyondTrust Privilege Management for Windows (aka PMfW) through 5.7, a SYSTEM installation causes Cryptbase.dll to be loaded from the use
HighCVSS 7.8No exploitEPSS 0%beyondtrust · privilege management for windowsDec 12, 2023
- CVE-2020-1261531Monitor
An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6.
HighCVSS 7.8No exploitEPSS 0%beyondtrust · privilege management for windowsDec 12, 2023
- CVE-2023-2363231Monitor
BeyondTrust Privileged Remote Access (PRA) versions 22.2.x to 22.4.x are vulnerable to a local authentication bypass.
HighCVSS 7.8No exploitEPSS 0%beyondtrust · privileged remote accessOct 12, 2023
- CVE-2024-401731Monitor
Privilege Escalation in U-Series Appliance
HighCVSS 7.8No exploitEPSS 0%beyondtrust · u-series applianceApr 19, 2024
- CVE-2024-401831Monitor
Privilege Escalation in U-Series Appliance
HighCVSS 7.8No exploitEPSS 0%beyondtrust · u-series applianceApr 19, 2024
- CVE-2020-1261431Monitor
An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6.
HighCVSS 7.8No exploitEPSS 0%beyondtrust · privilege management for windowsDec 12, 2023
- CVE-2024-2508331Monitor
An issue was discovered in BeyondTrust Privilege Management for Windows before 24.1.
HighCVSS 7.8No exploitEPSS 0%beyondtrust · privilege management for windowsFeb 16, 2024
- CVE-2018-1095930Monitor
Avecto Defendpoint 4 prior to 4.4 SR6 and 5 prior to 5.1 SR1 has an Untrusted Search Path vulnerability, exploitable by modifying environmen
HighCVSS 7.5No exploitEPSS 2%beyondtrust · avecto defendpointApr 17, 2019