An AI Found a Critical Security Hole in BeyondTrust. Hackers Were Inside It Four Days Later.
A new Google report shows how artificial intelligence is speeding up both the discovery of software flaws and their exploitation. One flaw found by an AI tool had attackers knocking within days of going public.

Key points
- CVE-2026-1731, a critical flaw in BeyondTrust remote-access software discovered by an AI research tool, was exploited in the wild within four days of public disclosure on 2026-02-06.
- The flaw carries a CVSS score of 9.9 out of 10, the near-maximum severity, and requires no password or user action to exploit.
- The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-1731 to its Known Exploited Vulnerabilities catalogue on 2026-02-13, giving federal agencies until 2026-02-16 to patch.
- Google's Threat Intelligence Group recorded 141 distinct exploited vulnerabilities in just the first eight months of 2026, already more than all 127 seen in 2025.
- Half of all AI-discovered vulnerabilities result in remote code execution, compared to 26% of those found through traditional methods.
A piece of software called Hacktron, an AI research agent built to hunt for security flaws automatically, found a serious hole in BeyondTrust's remote-access products sometime before February 2026. BeyondTrust makes tools that let IT teams connect to computers and servers from a distance, the kind of software used every day in hospitals, banks, and government offices. The flaw it found was a critical one.
What exactly is the flaw, and why does it matter?
CVE-2026-1731 is what security researchers call an "OS command injection" vulnerability: a weakness that lets an outside attacker send specially crafted instructions to a server and have the server obey them as if they came from a trusted administrator. No account. No password. No click from an employee needed.
The CVSS score, a standard 0-to-10 scale used to rate how dangerous a flaw is, came in at 9.9. That is nearly as bad as it gets. Successful exploitation can give attackers the ability to run any command they choose, pull out stored data, or knock the system offline entirely.
BeyondTrust's affected products are Remote Support (RS) and Privileged Remote Access (PRA). Both are widely used in managed IT services.
How did the attack timeline unfold?
The flaw went public on 2026-02-06. According to Google's Threat Intelligence Group (GTIG), whose findings were first reported by SecurityWeek, one group of attackers had weaponised it within four days. Five more groups followed within seven days of public disclosure.
That speed matters. The old assumption was that organisations had at least a few weeks to patch before criminals caught up. That window is closing.
| Event | Date |
|---|---|
| CVE-2026-1731 published | 2026-02-06 |
| First confirmed exploitation | Within 4 days of disclosure |
| CISA adds to exploited catalogue | 2026-02-13 |
| Federal patch deadline | 2026-02-16 |
The failure mode here is familiar: a critical patch drops, the advisory goes out, and defenders assume they have the weekend. In practice, the attackers have read the same advisory and are already writing the exploit.
What does the bigger Google report say?
GTIG tracked vulnerability disclosures from January 2025 through August 2026. Monthly disclosures roughly doubled, from 5,045 in January 2026 to 10,740 in August. High-risk disclosures grew 167% over the same period.
The exploitation side moved faster still. GTIG recorded an average of 18 exploited vulnerabilities per month in 2026, up from 10.5 per month in 2025. The group's analysis suggests attackers are increasingly using AI tools to read patch notes and proof-of-concept code and build working exploits quickly, rather than spending months finding brand-new zero-days (flaws unknown to the software maker).
The BeyondTrust case is the sharpest illustration of that trend in the report: an AI found the flaw, and other actors raced to use it before most organisations had time to respond.
If you work in IT or manage a team that uses BeyondTrust Remote Support or Privileged Remote Access, treat the patch for CVE-2026-1731 as already overdue.
Patch the thing before the postmortem template gets its own entry.



