
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-40140 is a pre-authentication denial-of-service vulnerability in BeyondTrust Remote Support and Privileged Remote Access, located in the network communication subsystem. Insufficient validation of client-supplied input allows an unauthenticated remote attacker to trigger a denial-of-service condition affecting appliance availability. Affected versions are Remote Support and Privileged Remote Access up to and including 25.3.2 (fixed in 25.3.3); some sources also reference a fix in 26.2.1 for certain product lines. It was published on July 6, 2026, with a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.7 (High) (GitHub Advisory, BeyondTrust Advisory).
The vulnerability is classified as CWE-400 (Uncontrolled Resource Consumption), meaning the affected network communication subsystem fails to properly control the allocation or maintenance of resources when processing client-supplied input. An unauthenticated attacker can send specially crafted network requests to the appliance, causing resource exhaustion or a crash that disrupts service availability. No authentication or user interaction is required, and the attack can be launched remotely over the network with low complexity. Attack patterns associated with this vulnerability include XML Ping of the Death (CAPEC-147) and Regular Expression Exponential Blowup (CAPEC-492), suggesting the flaw may involve malformed or resource-intensive input parsing (GitHub Advisory, BeyondTrust Advisory).
Successful exploitation results in a denial-of-service condition that disrupts the availability of BeyondTrust Remote Support and Privileged Remote Access appliances. There is no impact to confidentiality or integrity — the vulnerability is limited to availability. Because BeyondTrust Remote Support and Privileged Remote Access are enterprise remote access platforms often used for privileged session management, an outage could prevent administrators and support staff from accessing critical systems, potentially impacting business continuity and incident response capabilities (GitHub Advisory, BeyondTrust Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment classifies the vulnerability as automatable with no known exploitation. The EPSS score is approximately 0.56% (43rd percentile), indicating a relatively low but non-negligible probability of exploitation within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
BeyondTrust has released patched versions 25.3.3 (and 26.2.1 for certain product lines) for both Remote Support and Privileged Remote Access; upgrading to these versions is the primary recommended remediation (BeyondTrust Advisory). As a network-based workaround, organizations should implement network-level access controls (firewalls, allowlists) to restrict connectivity to BeyondTrust appliances to trusted networks and IP ranges only. Additionally, monitor appliance availability and configure alerting for unexpected service disruptions to enable rapid detection and response.
The vulnerability received broad coverage from security media outlets including BleepingComputer, The Hacker News, SC World, and CybersecurityNews, often grouped with related BeyondTrust CVEs (CVE-2026-40138, CVE-2026-40139) disclosed in the same advisory (BleepingComputer, The Hacker News). National CERTs including Singapore's CSA and Thailand's ThaiCERT issued advisories urging organizations to patch promptly. Community discussion on Mastodon and Bluesky noted the significance of pre-authentication vulnerabilities in privileged access management tools given BeyondTrust's history of high-profile exploitation in 2024–2025.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."