Authentication bypass vulnerability specific to BeyondTrust Remote Support with CVSS 9.2. Allows unauthenticated remote attackers to bypass access controls including elevated privilege accounts. BeyondTrust silently patched cloud deployments in April 2026 without public disclosure.
Upgrade to RS 25.3.3 or later immediately. Specific authentication configuration required but not disclosed by vendor; treat all instances as vulnerable unless confirmed otherwise. Implement network restrictions and audit logs thoroughly.
Source: BleepingComputer • Published: 2026-07-07
A high-severity path traversal zero-day affecting all ShareFile Storage Zone Controller 5.x and 6.x versions. Authenticated admin users can read arbitrary files, write malicious content to directories, or enumerate filesystem layout. Exploited in the wild starting July 10, 2026.
Install versions 5.12.5 and 6.0.2 immediately. Assume exposed systems are compromised and conduct forensic analysis. Review access logs for unauthorized file access. Consider systems in context of 2023 MOVEit Transfer attacks.
Source: BleepingComputer • Published: 2026-07-14
CVE-2026-40139: Authentication bypass vulnerability specific to BeyondTrust Remote Support with CVSS 9.2. Allows unauthenticated remote attackers to bypass access controls including elevated privilege accounts. BeyondTrust silently patched cloud deployments in April 2026 without public disclosure.