Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical RAVEN Vulnerability Exfiltrates Elasticsearch Databases
August 19, 2026
Oracle Patches Critical WebLogic CVE-2024-XXXX Allowing Full Takeover
August 19, 2026
Fake Claude Install Guide Deploys MacSync Stealer, Trojanizes Crypto Wallets
August 19, 2026
Home/CyberSecurity News/Critical BeyondTrust EPM Flaws Let Attackers Escalate Privileges
CyberSecurity News

Critical BeyondTrust EPM Flaws Let Attackers Escalate Privileges

Key Takeaways BeyondTrust has disclosed two high-severity vulnerabilities affecting its Endpoint Privilege Management (EPM) for Windows. The flaws, CVE-2026-40144 and CVE-2026-40145, could allow...

Jennifer sherman
Jennifer sherman
August 19, 2026 3 Min Read
3 0

Key Takeaways

  • BeyondTrust has disclosed two high-severity vulnerabilities affecting its Endpoint Privilege Management (EPM) for Windows.
  • The flaws, CVE-2026-40144 and CVE-2026-40145, could allow local attackers to escalate privileges or bypass security controls.
  • All versions of BeyondTrust EPM (Windows Deployment) prior to 26.1.2 are affected.
  • BeyondTrust discovered the issues internally and has found no evidence of exploitation in the wild.
  • A patch is available, and organizations should update to version 26.1.2 or later immediately.

Critical BeyondTrust EPM Flaws Expose Windows Systems to Privilege Escalation

BeyondTrust has issued a security advisory detailing two high-severity vulnerabilities within its Endpoint Privilege Management (EPM) product for Windows. These critical flaws could enable malicious actors with local access to a system to elevate their privileges or circumvent crucial anti-tamper mechanisms designed to protect the EPM solution itself.

Table Of Content

  • Key Takeaways
  • Critical BeyondTrust EPM Flaws Expose Windows Systems to Privilege Escalation
  • CVE-2026-40144: Kernel Privilege Escalation
  • CVE-2026-40145: Anti-Tamper Bypass
  • What You Should Do

The vulnerabilities, identified as CVE-2026-40144 and CVE-2026-40145, impact all iterations of BeyondTrust Endpoint Privilege Management (Windows Deployment) released before version 26.1.2. The company formally announced these issues in advisory BT26-04 on August 17, 2026.

According to BeyondTrust, these security defects were uncovered during internal security assessments, which leveraged advanced AI models and proprietary testing frameworks. The vendor stated that, at the time of remediation, there was no indication that either vulnerability had been exploited by external threat actors.

CVE-2026-40144: Kernel Privilege Escalation

The more severe of the two vulnerabilities, CVE-2026-40144, has been assigned a CVSS v4 score of 7.3, categorizing it as high severity. This flaw is an out-of-bounds read, classified as CWE-125, residing within a kernel-mode component of BeyondTrust EPM for Windows.

The root cause of this vulnerability lies in insufficient input validation within the affected kernel component. A local attacker, operating with standard, non-administrative user privileges, could exploit this weakness to force the component to access memory beyond its allocated boundaries.

Successful exploitation of CVE-2026-40144 could lead to kernel memory corruption and the execution of arbitrary code in kernel mode. Given that kernel mode operates at the highest privilege level within a Windows operating system, an attacker could achieve complete control over the compromised endpoint.

While this vulnerability requires local access, meaning it cannot be directly exploited remotely, local privilege escalation bugs are frequently a critical component of sophisticated attack chains. Threat actors often leverage such flaws after gaining an initial foothold on a system through other means, such as phishing, malware deployment, or stolen credentials, to escalate their access from a low-privileged user to full system administrator.

CVE-2026-40145: Anti-Tamper Bypass

The second vulnerability, CVE-2026-40145, carries a CVSS v4 score of 7.1. This issue is categorized as an insufficient access control vulnerability (CWE-1220), stemming from how a BeyondTrust EPM support utility interacts with the product’s built-in anti-tamper protections.

Under specific, predefined conditions, the security protections intended for the support utility process may not be correctly enforced. This could allow an attacker who has already achieved elevated privileges on an endpoint to manipulate the utility, thereby executing code outside the intended scope of EPM’s anti-tamper controls.

Unlike CVE-2026-40144, this flaw mandates that an attacker already possesses elevated privileges, local access, and specific endpoint preconditions. While CVE-2026-40145 does not provide an initial pathway to administrative access, it could significantly aid attackers in weakening existing security controls once they have already gained a privileged position on a system.

BeyondTrust has fixed both issues in Endpoint Privilege Management (Windows Deployment) version 26.1.2. Organizations utilizing affected versions are strongly advised to upgrade their endpoints to version 26.1.2 or a newer release without delay.

What You Should Do

  • Immediately upgrade all BeyondTrust Endpoint Privilege Management (Windows Deployment) installations to version 26.1.2 or a later release.
  • Review system logs for any unusual local privilege escalation attempts.
  • Monitor for unexpected kernel-level crashes or suspicious process behavior involving EPM support utilities.
  • Investigate any attempts to disable or interfere with endpoint security controls.
  • Reinforce the principle of least privilege across your environment to minimize the impact of any potential local compromise.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitMalwarePatchphishingSecurityVulnerability

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Google Patches Critical Chrome WebGL and Dawn Flaws

Next Post

Fake Claude Install Guide Deploys MacSync Stealer, Trojanizes Crypto Wallets

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
CISA Warns of VMware vCenter Path Traversal Vulnerability Actively Exploited in Attacks
August 19, 2026
Critical Cursor 0-day Vulnerability Allows Arbitrary Code Execution
August 19, 2026
Critical Microsoft Copilot CoSnitch Flaw Lets Attackers Steal Sensitive Data
August 19, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us