Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Critical BeyondTrust Vulnerability Exploited in the Wild to Gain Full Domain Control

A critical vulnerability identified as CVE-2026-1731 is actively exploited, allowing attackers to gain full domain control over affected systems. This vulnerability enables threat actors to remotely execute operating system commands without…

A critical vulnerability identified as CVE-2026-1731 is actively exploited, allowing attackers to gain full domain control over affected systems. This vulnerability enables threat actors to remotely execute operating system commands without authentication.

The exploit occurs in self-hosted BeyondTrust deployments, permitting unauthenticated users to run arbitrary OS commands through specially crafted HTTP requests. These commands execute under the site user's privileges.

Cloud-hosted BeyondTrust instances received automatic patches on Feb 2, 2026. However, self-hosted users must manually apply updates to mitigate risks.

Arctic Wolf's analysis indicates attackers using SimpleHelp Remote Access binaries in post-exploitation activities. These were created through BeyondTrust Bomgar processes under the SYSTEM account and stored in the ProgramData directory, usually named remote access.exe .

Attackers utilized net user and net group commands to establish privileged domain accounts, granting Enterprise Admin or Domain Admin rights. For reconnaissance, the AdsiSearcher function was employed to enumerate Active Directory computers , alongside network discovery commands such as net share , ipconfig /all , and systeminfo .

A critical vulnerability identified as CVE-2026-1731 is actively exploited, allowing attackers to gain full domain control over affected systems.
Rachel Green · Thehackingpost

Product Affected Versions Fixed Versions

Remote Support (RS) 25.3.1 and prior Patch BT26-02-RS (v21.3–25.3.1)

Privileged Remote Access (PRA) 24.3.4 and prior Patch BT26-02-PRA (v22.1–24.X)

Arctic Wolf investigators noted the utilization of PSExec and Impacket SMBv2 session setup requests, indicating a coordinated spread of the SimpleHelp tool across multiple networked hosts.

Advertisement

Security experts recommend immediate patching of all vulnerable versions. Cloud-based BeyondTrust customers are already protected. CISA advises that self-hosted deployments with versions older than RS 21.3 or PRA 22.1 must be upgraded before applying the patch.

Administrators should inspect systems for unauthorized SimpleHelp binaries, suspicious admin accounts, and unusual network traffic related to SMB sessions.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories