iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Yes—BeyondTrust’s former Bomgar remote-support products were targeted. CVE-2026-1731 is a critical pre-authentication remote-code-execution flaw that can let an unauthenticated attacker run operating-system commands, access data, disrupt services, and potentially use a trusted support system to reach customer networks.
BeyondTrust reported exploitation attempts beginning February 10, 2026, against unpatched, internet-facing self-hosted appliances. The episode is best described as a documented sequence of serious vulnerabilities and active-exploitation reports, not as proof of a quantified, industry-wide “surge.”
What “Bomgar exploitation” means now
Bomgar is the legacy name associated with BeyondTrust Remote Support and Privileged Remote Access. Current security advisories use the BeyondTrust product names, but many IT teams, managed service providers (MSPs), and customers still refer to the deployments as Bomgar.
Recommended Free Tools
CVE-2026-1731 affects the control plane before authentication. In practical terms, an attacker does not need a valid support-session login to attempt operating-system command execution on a vulnerable appliance. From there, the consequences can include unauthorized access, data exfiltration, service disruption, and use of the appliance’s trusted position as a stepping stone into connected environments.
#1 Best Overall
- Prevent Lost Remotes & Devices: The 6.5 ft retractable remote control tether keeps TV remotes, gaming controllers, and tablets securely attached and always within reach. No more searching under furniture.
- Flexible Curve-Fitting Adhesive Base: Designed with a strong non-damaging adhesive pad that securely mounts on curved or flat surfaces. Provides a stable hold for remotes, controllers, and speakers.
- 6.5 Ft Retractable Cable Design: Features a smooth retractable steel cable with one-touch release for flexible movement. Keeps devices organized while allowing comfortable daily use.
- Heavy Duty Security Construction: Built with impact-resistant housing and reinforced steel cable for reliable protection. Includes 2 extra adhesive pads and 2 hex tools for easy installation.
- Easy Installation & Wide Compatibility: Apply the adhesive pad and allow proper setting time before use. Works with streaming remotes, gaming controllers, tablets, and retail display devices at home or work.
BeyondTrust says the observed attempts were limited to internet-facing, self-hosted systems that had not been patched before February 9, 2026. SaaS instances were fully patched, and patches were automatically deployed to instances with the update service enabled.
Which products and versions are affected?
| Product | Affected versions | Fixed version | Advisory details |
|---|---|---|---|
| BeyondTrust Remote Support | 25.3.1 and prior | 25.3.2 or later, or the applicable product patch | CVE-2026-1731; CVSSv4 9.9; BeyondTrust BT26-02 (2026) |
| BeyondTrust Privileged Remote Access | 24.3.4 and prior | 25.1 or later, or the applicable product patch | CVE-2026-1731; CVSSv4 9.9; BeyondTrust BT26-02 (2026) |
| Remote Support and Privileged Remote Access family | Versions covered by the December 2024 advisory | Use the fixed release specified in BT24-10 | CVE-2024-12356; unauthenticated command injection; CVSSv3 9.8 |
Do not treat a version number alone as proof that an appliance is safe. Confirm the product-specific patch, update status, and whether the appliance was reachable from the internet during the exposure window.
Rank #2
- One-touch control for your entire home: Arm or disarm your ADT Blu security system with a single button press from up to 75 feet away, no keypad or phone required.
- Panic button backed by ADT: With a professional monitoring plan, press and hold to send a direct emergency signal to ADT's monitoring centers so help is on the way fast.
- Always within reach: Compact design with a built-in keychain ring keeps your home security controls in your pocket or clipped to your keys.
- Smart status alerts built in: The LED indicator notifies you when the remote is out of range or the battery is running low, so you are never caught off guard.
- Fully integrated with ADT Blu: Pairs directly with your ADT Blu Base and works alongside every ADT Blu device for a connected, expandable home security setup.
Timeline of the 2026 incident
| Date | What happened |
|---|---|
| January 31, 2026 | BeyondTrust detected anomalous activity on one Remote Support appliance; a researcher validated the vulnerability. |
| February 2, 2026 | Patches were issued and automatically deployed where the update service was enabled. BeyondTrust says SaaS instances were fully patched. |
| February 6, 2026 | BeyondTrust published advisory BT26-02 and CVE-2026-1731. |
| February 10, 2026 | BeyondTrust observed initial exploitation attempts. |
| December 16, 2024 | Advisory BT24-10 disclosed CVE-2024-12356, a separate critical unauthenticated command-injection flaw affecting the same product family. |
The earlier CVE-2024-12356 disclosure matters because it shows that remote-access infrastructure remains a recurring, privileged-risk surface. It does not establish that the two vulnerabilities were used in the same intrusion.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallWhy a remote-support flaw becomes a supply-chain problem
One trusted tool can serve many organizations
NSA, CISA, and MS-ISAC describe remote-monitoring and management (RMM) software as common infrastructure for MSPs and help desks. These tools can manage endpoints, monitor networks, transfer files, and open administrative sessions. A compromised provider appliance or account may therefore inherit the provider’s legitimate trust and reach into multiple customer tenants.
Rank #3
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Security controls may treat the activity as legitimate
Normal support traffic often uses approved accounts, signed agents, and expected administration protocols. The joint NSA, CISA, and MS-ISAC guidance warns that malicious use of RMM software can bypass antivirus and anti-malware defenses. The risk is not that every customer was compromised; it is that one trusted access path can make downstream activity harder to distinguish from routine support.
What is not established
The BT26-02 material does not publish a count or percentage of affected customers, so a broad numerical “surge” cannot be claimed from these advisories alone. CISA’s January 6, 2025 Treasury update said it was working with the Treasury Department and BeyondTrust to understand and mitigate that incident and had no indication at that time that other federal agencies were impacted. That short update is not a complete breach-scope report.
Rank #4
- Compatibility Infomation:Compatible with LiftMaster,Chamberlain,and Craftsman garage door openers manufactured from 1993 to the present day,this remote supports Two different frequencies of security rolling codes. Whether you're part of a multi-car family or need a replacement for lost or damaged remotes, our solution ensures hassle-free operation.
- Small & Portable:A simple design with its small size and lightweight keychain, makes the remote perfect for attaching to your car key ring, pocket, or elsewhere, ensuring easy portability.
- Easy to Set and Use:With its dual-color LED light design, the pairing process of the garage door becomes clearer and simpler. Say goodbye to complicated setups and enjoy a more pleasant and convenient user experience.
- Safe & Reliable:The system employs the latest rolling code technology, minimizing radio wave interference while bolstering security. Each time the remote is used, a new security code is generated, providing a robust defense against potential intruders and ensuring the safety of your property.
- Wide Signal Coverage:With a signal coverage range of up to 164 feet, it allows for remote control of door opening and closing. You can conveniently use the remote to unlock the door directly from your car as you approach home, enhancing your travel convenience.
How to check whether a Bomgar or BeyondTrust appliance was exposed
- Inventory every deployment. Include Remote Support and Privileged Remote Access appliances, cloud-managed instances, supplier-managed systems, disaster-recovery appliances, and environments owned by an MSP.
- Verify the patch level. Confirm Remote Support is on 25.3.2 or the applicable BT26-02 fix, and Privileged Remote Access is on 25.1 or the applicable fix. Record whether automatic updates were enabled and completed.
- Determine internet exposure. Identify public addresses, forwarded ports, reverse proxies, administrative interfaces, and firewall rules that made a self-hosted appliance reachable from the internet before February 9.
- Preserve and review logs. Examine appliance, authentication, session, file-transfer, API, firewall, and endpoint-detection-and-response (EDR) records beginning no later than January 31, 2026. Look for unexpected requests, new administrators, unusual session starts, file transfers, command execution, configuration changes, and outbound connections.
- Check connected tenants and credentials. If the appliance or provider account may have been accessed, identify every customer and internal system reachable through it. Rotate exposed credentials, tokens, API keys, and privileged passwords according to your incident-response plan.
- Escalate as a third-party incident. Coordinate with BeyondTrust, your MSP, legal counsel, cyber-insurance carrier, and incident-response provider. Notify affected customers when your investigation establishes a reasonable risk, rather than waiting for a complete forensic picture.
Monitoring and containment controls
- Use EDR to monitor the appliance and endpoints for unexpected shells, scripting engines, credential access, persistence, and lateral movement.
- Build a baseline of normal remote-support users, hours, source networks, destinations, session types, and file-transfer volume; investigate deviations rather than relying only on malware signatures.
- Allowlist approved remote-access tools and remove or disable unauthorized RMM software.
- Restrict inbound and outbound RMM traffic to approved paths, networks, VPNs, or virtual desktop infrastructure. Block unnecessary ports and protocols identified in your environment.
- Apply least privilege to support accounts, separate provider administration from customer administration, require strong authentication, and review dormant accounts and emergency access.
- Send appliance, identity, firewall, session, and EDR events to a SIEM so activity can be correlated across the provider and customer environments.
“Malicious use of RMM software allows cybercriminals and advanced persistent threat (APT) actors to bypass anti-virus/anti-malware defenses.” — NSA, CISA, and MS-ISAC joint guidance, January 25, 2023
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
What MSPs and customers should change after patching
Patching closes the known vulnerability; it does not prove that no one used it beforehand. MSPs should document each tenant’s exposure, preserve evidence, and provide customers with clear dates, affected appliance identifiers, observed indicators, and credential-reset requirements. Customers should require that same information from providers and verify that remote-support access is limited to approved staff and systems.
Best Value
- [Keep Your Remote Always Within Reach] Stop searching under sofas or cushions with this remote control tether designed for TV remotes and streaming devices. The 6.5 ft retractable cable keeps your remote securely attached while allowing comfortable movement during everyday entertainment
- [Durable Cable Built for Daily Remote Use] Featuring a reinforced steel retractable cable and impact-resistant housing, this tv remote tether provides reliable attachment for frequently used remotes. The smooth retractable design supports repeated pulling while keeping devices organized
- [Works with TVs, Controllers and More] Designed as a versatile remote control leash, this accessory helps secure TV remotes, gaming controllers, tablets, and small electronic devices. Ideal for living rooms, game rooms, offices, hotels, and display areas
- [Flexible Adhesive Mounting Design] The curve-fitting adhesive base attaches securely to flat or curved surfaces without complicated installation. Includes extra adhesive pads and hex tools, making setup and replacement simple for different remote control setups
- [Practical Accessory for Home Entertainment] A useful remote control tether solution for families, entertainment spaces, and commercial environments. Keep frequently used remotes organized and accessible while adding convenience to your daily TV experience
For future procurement and reviews, compare remote-access services on self-hosted versus SaaS exposure, patch automation, internet exposure, pre-authentication attack surface, session and file-transfer logging, EDR and SIEM integration, allowlisting and least-privilege controls, multi-tenant blast radius, and incident-response support. No single deployment model eliminates supply-chain risk; it changes where the customer must place controls and oversight.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

