CVE-2026-1731: BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
EPSS90.8%KEV 1739件中448位
CVEの年2026同じ年に追加
同じベンダーの登録3
同じ製品の登録1
| 項目 | 内容 |
|---|---|
| ベンダー | BeyondTrust |
| 製品 | Remote Support (RS) and Privileged Remote Access (PRA) |
| 脆弱性の名前 | BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability |
| KEVへの追加日 | 2026年2月13日 |
| 米政府機関の対応期限 | 2026年2月16日 |
| ランサムウェアでの悪用 | 確認あり |
| CWE | CWE-78 |
CISAの説明(英語)
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of the site user. Successful exploitation requires no authentication or user interaction and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption.
CISAの既知の悪用された脆弱性カタログ(KEV)のデータです。EPSSはFIRSTが公表する「今後30日以内に悪用が観測される確率」の推定値で、週1回更新しています。対応は必ず各ベンダーの公式情報に従ってください。
このページについて
2026年2月13日にCISAの既知の悪用された脆弱性カタログ(KEV)に追加された、BeyondTrustのRemote Support (RS) and Privileged Remote Access (PRA)の脆弱性です。