CVE-2026-1731 is a critical vulnerability, which affects BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA).
The flaw is a pre‑authentication remote code execution stemming from improper handling of specially crafted requests allowing an unauthenticated remote attacker to execute operating system commands in the context of the site user. Users are advised to update their appliances to the latest version.
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.
References:

