BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA
BeyondTrust has fixed four vulnerabilities, including two critical pre-authentication authentication bypass flaws (CVSS 9.2), in its Remote Support and Privileged Remote Access products.
Intelligence analysis by Llama

BeyondTrust shipped patches for two critical pre-auth authentication bypass flaws (CVSS 9.2) in Remote Support and Privileged Remote Access, plus a DoS bug and an authenticated privilege issue. The bugs were found internally with help from Anthropic's Claude Opus 4.8 model and the company's own tooling.
BeyondTrust makes tools that let helpers remotely fix computers, and the company found some really bad holes in the locks on those tools. With the worst holes, someone on the internet could walk in without a key, but only if a certain door setting was turned on. The good news is that they already shipped a fix, so people just need to update.
Analysis
AI as an Internal Bug Hunter
The most striking detail in BeyondTrust's disclosure is not the severity score but the toolchain behind the discoveries. The company says all four flaws were identified internally during ongoing security assessments, with help from Anthropic's Claude Opus 4.8 model and BeyondTrust's own proprietary research tooling. Large language models have rapidly moved from code-completion toys to plausible participants in offensive and defensive security work, and this disclosure is one of the more concrete public examples of an enterprise vendor leaning on a frontier model to find pre-authentication authentication bugs in its own shipping product. The findings also underline a double-edged reality: the same class of model that helped defenders can be pointed at the same code by attackers looking for the same class of weakness.
Configuration Is the Catch
Both of the headline-grabbing CVSS 9.2 issues, CVE-2026-40138 and CVE-2026-40139, are pre-authentication authentication-bypass flaws, which would ordinarily be enough on their own to send administrators into a patching sprint. BeyondTrust, however, qualifies the severity by noting that successful exploitation hinges on a specific authentication configuration being enabled. The fourth bug, CVE-2026-40141, similarly narrows real-world risk by requiring an already-authenticated user with particular permissions. That nuance matters for prioritisation: defenders who know they have the relevant configuration off can breathe slightly more easily, while those running the affected setups are looking at remote, unauthenticated takeover of an appliance that brokers access to the rest of the estate.
A Pattern of Targeting BeyondTrust Appliances
BeyondTrust stresses that it has no evidence of in-the-wild exploitation of these specific CVEs, but the company has not been a stranger to attacker attention. Past flaws in RS and PRA, including CVE-2024-12356 and CVE-2026-1731, have been repeatedly weaponised to drop web shells and backdoors on internet-exposed appliances. That history reframes the "configuration matters" caveat: even a conditional bypass on a product that attackers already know how to pivot through is a high-priority patch. Organisations running RS or PRA 25.3.2 or below should treat the move to 25.3.3 as urgent, and treat any appliance that cannot be patched immediately as a candidate for network segmentation and heightened monitoring until it can.
Key points
- BeyondTrust patched four flaws in Remote Support and Privileged Remote Access, two rated CVSS 9.2 for pre-authentication authentication bypass.
- The two critical issues, CVE-2026-40138 and CVE-2026-40139, require a specific authentication configuration to be exploitable.
- CVE-2026-40140 (CVSS 8.7) can be triggered for denial of service, while CVE-2026-40141 (CVSS 8.5) requires an already-authenticated user with particular rights.
- BeyondTrust credits Anthropic's Claude Opus 4.8 model and its own tooling with helping to find the bugs during internal assessments.
- Fixes ship in RS 25.3.3 and PRA 25.3.3, and the company has seen no evidence of in-the-wild exploitation, though past RS/PRA bugs have been heavily abused.
If organisations apply the 25.3.3 patches promptly and audit whether the specific authentication configuration tied to the two CVSS 9.2 bugs is enabled, the window of exposure can close quickly with little to no attacker dwell time. Continued use of AI-assisted code review inside vendor security teams may also surface similar issues earlier in the development cycle for future releases.
BeyondTrust appliances have a track record of being targeted even before public patches land, and a pre-authentication bypass on a privileged-access gateway is exactly the kind of bug that gets quietly stockpiled by sophisticated actors. If the relevant authentication configuration is widely enabled in the wild, opportunistic mass scanning for these CVEs could quickly follow disclosure, and appliances that cannot be patched on schedule will become high-value footholds for ransomware and espionage operators.



