2026-07-08HIGHNCSC-CH flags critical pre-auth bypass in BeyondTrust RS/PRA appliances (CVE-2026-40138/-40139)
BeyondTrust RS/PRA unauthenticated DoS (network-communication subsystem), BT26-03
cve · CVE-2026-40140
Coverage
1
first 2026-07-08 → last 2026-07-08
Latest activity
2026-07-08
NCSC-CH flags critical pre-auth bypass in BeyondTrust RS/PRA appliances (CVE-2026-40138/-40139)
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, technology · regions: switzerland
Sources cited
3
3 hosts
Action items (2)
Do-now tasks recorded on the entries about CVE-2026-40140, newest first. Check the date before acting on an older one.
- Patch BeyondTrust Remote Support / Privileged Remote Access to ≥ 25.3.3 now (self-hosted); cloud instances were fixed 2026-04-21.2026-07-08CVE-2026-40138 +3
- Until patched, determine whether the non-default authentication configuration required for CVE-2026-40138/-40139 (likely a SAML/OIDC integration) is enabled and disable it if not operationally required; restrict appliance management-plane access to a trusted admin segment.2026-07-08CVE-2026-40138 +3
Defender insights
What each entry about CVE-2026-40140 tells a defender to do, newest first.
Story timeline
Hunting pivots
Entries about BeyondTrust RS/PRA unauthenticated DoS (network-communication subsystem), BT26-03 (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- BeyondTrust RS/PRA authenticated broken-access-control (resource access beyond scope), BT26-03×1
- BeyondTrust RS/PRA pre-auth authentication bypass (CVSS4 9.2), NCSC-CH BT26-03×1
- BeyondTrust RS/PRA pre-auth authentication bypass (CVSS4 9.2), NCSC-CH BT26-03×1
Where this entity is cited
Source distribution
- bleepingcomputer.com1 (33%)
- security-hub.ncsc.admin.ch1 (33%)
- thehackernews.com1 (33%)
External references
All cited sources (3)
- security-hub.ncsc.admin.chprimaryNCSC Switzerland (GovCERT.ch), Cyber Security Hubhttps://security-hub.ncsc.admin.ch/#/posts/12751
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/beyondtrust-warns-of-critical-flaws-in-remote-access-software/
- thehackernews.comThe Hacker Newshttps://thehackernews.com/2026/07/beyondtrust-patches-critical-auth.html