22 July 2026

CyberArk: CA26-35 / CA26-36

Dear Customers, On Wednesday, July 22, Idira (formerly CyberArk) has released Critical and High Severity Security Bulletins CA26-35, CA26-36 affecting z/OS Credential Provider, Terminal plugin controller (TPC),Microsoft Windows Local with WMI plugin, Database Credentials Management Framework versions.

 

Please review whether any affected components are present within your environment and prioritize remediation efforts based on the severity and business impact outlined in the associated security bulletins.

 

CA26-35 involves a Critical severity issue that affects z/OS Credential Provider, all versions prior to 14.2.7
CA26-36 involves a High severity issue that affects Terminal plugin controller (TPC), version 15.0.0 or earlier; Microsoft Windows Local with WMI plugin, version 21.0.1 or earlier; Database Credentials Management Framework, version 20.1.8 or earlier.

 

For complete details on the vulnerabilities, recommendations, and update instructions, please review the Security Bulletins, that can be found in the Technical Community:

 

https://www.cyberark.com/CA26-35
https://www.cyberark.com/CA26-36

 

Learn more by visiting Product Security | CyberArk



8 July 2026

Wednesday, July 8th, CyberArk released Security Bulletins CA26-24, CA26-25, CA26-27, CA26-28 and CA26-29

CA26-24 involves a High severity issue that affects EPM SaaS Windows Agents, all versions prior to 26.6.

 

CA26-25 involves a High severity issue that affects EPM SaaS Windows Agents, all versions prior to 26.6.

 

CA26-27 involves a High severity issue that affects Privileged Threat Analytics, Idira PAM Self-Hosted, all versions prior to version 15.2 (exclusive).

 

CA26-28 involves a High severity issue that affects Vault/Infra, Self-Hosted, all versions prior to version 15.0.3 (inclusive).

 

CA26-29 involves a High severity issue that affects Remote Control Client, all versions prior to version 15.0.3 (inclusive).

 

For complete details on the vulnerabilities, recommendations, and update instructions, please review the Security Bulletins, that can be found in the Technical Community:

https://www.cyberark.com/CA26-24

https://www.cyberark.com/CA26-25

https://www.cyberark.com/CA26-27

https://www.cyberark.com/CA26-28

https://www.cyberark.com/CA26-29

 

Learn more by visiting Product Security | CyberArk



6 July 2026

BeyondTrust Remote Support and Privileged Remote Access Security Advisory: BT26-03

Action Required
BeyondTrust has published Security Advisory BT26-03 (https://www.beyondtrust.com/trust-center/security-advisories) relating to multiple vulnerabilities affecting BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA).

Customers using self-hosted BeyondTrust Remote Support or Privileged Remote Access should review their current versions and ensure that the relevant security updates have been applied.

 

Impact
The advisory includes Critical and High severity vulnerabilities. The most severe vulnerabilities may allow an unauthenticated attacker to bypass access controls and gain unauthorised access to the appliance under specific configurations. Additional vulnerabilities may result in service disruption, unintended data access, or elevated access by an authenticated user with specific permissions.

The affected versions are:

  • Remote Support RS 25.3.2 or lower
  • Privileged Remote Access PRA 25.3.2 or lower

Current Status
BeyondTrust has confirmed that patches have already been applied to all RS/PRA cloud customers.

Self-hosted customers should apply the relevant April 2026 Security Rollup for their deployed version where automatic updates are not enabled, or upgrade to:

  • Remote Support RS 25.3.3 or above
  • Privileged Remote Access PRA 25.3.3 or above

Recommended Action
Customers should review the BeyondTrust BT26-03 Security Advisory and confirm whether their environment is affected.

Where required, customers should apply the relevant security rollup or upgrade to the fixed versions as soon as possible, particularly where Remote Support or Privileged Remote Access is externally accessible.



13 June 2026

Advisory ID: BT26-02

CVE-2026-1731

 

BeyondTrust Remote Support and older versions of Privileged Remote Access contain a critical pre-authentication remote code execution vulnerability that may be triggered through specially crafted client requests. Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of the site user and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption.

 

  • Synopsis: Remote code execution in Remote Support (RS) and Privileged Remote Access (PRA)
  • Affected Product: Remote Support (RS) and Privileged Remote Access (PRA)

 

Observed exploitation activity has been limited to internet-facing, self-hosted environments where the patch had not been applied before February 9, 2026.

 

Important: BeyondTrust is strongly encouraging all self-hosted customers who had internet-exposed instances that remained unpatched as of February 9 to take immediate action to apply the recommended updates and open a “Severity 1” ticket to BeyondTrust support, citing “BT26-02” in the description.

 

Affected Versions:

Remote Support – 25.3.1 and prior

Privileged Remote Access – 24.3.4 and prior



1 2 3 12