July 8, 2026
- BeyondTrust patched two critical pre-auth flaws in Remote Support (RS) and Privileged Remote Access (PRA), including CVE-2026-40138 (CVSS 9.2), that let unauthenticated attackers take over affected appliances. Given these products' privileged position, prioritize patching. BleepingComputer, The Hacker News · Vulnerabilities & Exploits
in Synacktiv Drops a Kerberos Reflection Bypass That Hands Attackers SYSTEM