BeyondTrust, a widely used remote access and support platform, has confirmed critical security flaws in its Remote Support and Privileged Remote Access (PRA) products. If your business or IT provider uses BeyondTrust to remotely manage systems, this needs attention now.
- What it is: Four vulnerabilities were disclosed, including two rated critical (CVSS 9.2) that could let an attacker bypass authentication entirely.
- Who is affected: Organisations running self-hosted (on-premises) BeyondTrust Remote Support or Privileged Remote Access, version 25.3.2 or earlier. Cloud-hosted customers were already patched automatically.
- What the risk is: A successful attack could hand control of the remote access appliance to an outsider, potentially exposing every device it manages.
- What action is needed: Self-hosted customers should apply BeyondTrust's April 2026 Security Rollup, or upgrade to version 25.3.3 or later, as soon as possible.
If you are unsure which version your organisation is running, we recommend checking with your IT provider today rather than waiting for the next scheduled maintenance window.