Menu
BREAKING NEWS

BeyondTrust CVE-2026-40138: Critical RMM Bypass Flaw

Uday Patil Jul 7, 2026 5 min read 53 views
BeyondTrust CVE-2026-40138: Critical RMM Bypass Flaw

Three months. Three critical vulnerabilities in the software that enterprises trust to remotely manage their networks. If you are starting to notice a dangerous pattern, you are not imagining it.

BeyondTrust recently disclosed four vulnerabilities in its highly popular Remote Support (RS) and Privileged Remote Access (PRA) products. The two most severe—CVE-2026-40138 and CVE-2026-40139—are critical authentication bypass flaws carrying a massive CVSS score of 9.2.

Just like we recently saw with the SimpleHelp RMM vulnerability, attackers are actively hunting for flaws in the exact tools used by IT teams. If your company relies on BeyondTrust for remote access, here is what you need to know before your network gets breached.

The Hidden Reality: A Bypass With One Catch

Most security teams assume an authentication bypass means an attacker can simply walk through the front door. The reality of CVE-2026-40138 and CVE-2026-40139 is slightly more complex, but equally devastating.

These flaws live in the authentication subsystem. Improper validation allows an attacker to completely bypass access controls and gain unauthorized access to the appliance—including accounts with administrator-level privileges. No valid credentials or passwords are needed.

However, here is the critical nuance that 95% of IT admins miss: exploitation requires a specific authentication configuration to be enabled. This isn’t a flaw that affects every single deployment by default. The difference between “patch when convenient” and “emergency patch tonight” depends entirely on how your organization configured the authentication settings. That single detail gets missed when security bulletins are quickly skimmed.

The Standard Advice (And Why It Backfires)

The reflexive response to any BeyondTrust advisory is: “Patch the appliance immediately.” While necessary, treating patching as the only solution will backfire.

BeyondTrust serves over 20,000 customers globally, including a massive share of the Fortune 100. That scale makes it a prime target for Advanced Persistent Threats (APTs). In a previous incident, a Chinese state-linked group weaponized separate BeyondTrust zero-days to breach the U.S. Treasury Department. Security researchers discovered that the attack chain required combining the BeyondTrust flaw with a second vulnerability in an underlying database tool.

If you only patch the headline CVE without deeply auditing your environment for secondary flaws, you are leaving backdoor paths wide open for sophisticated threat actors.

The Edge Case: Configuration Over Version Numbers

Most enterprise patch-management workflows are built around one simple question: “Is the software up to date?”

For this specific BeyondTrust vulnerability, checking the version number is not enough. Because exploitation depends on a specific authentication configuration, two organizations running the exact same vulnerable software version can have completely different risk levels.

This is the edge case where automated patch tickets fail. Confirming the patch is installed answers one question, but manually confirming your authentication configuration doesn’t match the exploitable condition answers the question that actually matters.

The Advanced Fix: Remote Access Audit Checklist

Don’t wait for threat actors to begin active exploitation. Run through this emergency checklist immediately:

  • Review Authentication Configurations: Do not rely on version numbers alone. Audit the appliance’s authentication settings directly to determine if you meet the specific conditions required for exploitation.
  • Apply the Vendor Patch: Immediately update both Remote Support and Privileged Remote Access platforms. If you use the SaaS version, verify with BeyondTrust that your instance has been updated.
  • Audit Elevated-Privilege Accounts: Review access logs for any administrator accounts that may have been created or accessed without a clear administrative trail, especially if your instance is internet-facing.
  • Monitor for Denial of Service: Watch for appliance availability issues tied to the related CVE-2026-40140 flaw. A successful denial-of-service attempt can look like routine downtime rather than an active intrusion attempt.

What Happens Next

SimpleHelp. Microsoft SharePoint. Now BeyondTrust. Three critical vulnerabilities in three months, all in software designed to give IT teams privileged access to other systems.

This is not a coincidence. Attackers are focusing their research efforts here because a single flaw in the right remote-access tool can open the door to thousands of downstream organizations at once. Treat your remote access utilities with the same intense scrutiny as your public web servers.

Frequently Asked Questions

What are BeyondTrust CVE-2026-40138 and CVE-2026-40139?
They are critical authentication bypass vulnerabilities (CVSS 9.2) in BeyondTrust Remote Support and Privileged Remote Access. They allow attackers to bypass access controls and reach elevated-privilege accounts without valid credentials.

Are these BeyondTrust vulnerabilities being actively exploited?
As of July 2026, there are no widespread reports of in-the-wild exploitation. However, given the platform’s history of being targeted by state-sponsored actors, organizations must patch proactively before active exploitation begins.

Do I need to worry if I use the SaaS version of BeyondTrust?
SaaS instances are typically patched directly by the vendor. However, self-hosted (on-premises) deployments require manual patching and configuration reviews, and are historically where exploitation concentrates.

For a complete tracker of all critical 2026 vulnerabilities, see our Enterprise CVE Security Hub.


Reported by CyberUpdates365 Desk

Delivering the latest insights on enterprise security, federal AI directives, and the future of IT infrastructure. Follow us for daily updates on how technology is reshaping the corporate landscape.

Author

  • Uday Patil

    Uday Patil is a Cybersecurity Researcher, DevSecOps Engineer, and the Founder of CyberUpdates365. Specializing in Threat Intelligence and Zero-Day vulnerability analysis, Uday is dedicated to breaking down complex cyber threats into actionable insights. His mission is to empower developers and security teams worldwide with rapid alerts, remediation scripts, and practical guidance to stay ahead of the evolving threat landscape.