CISA tells agencies to patch the BeyondTrust bug now


  • CISA has added two bugs found in BeyondTrust products
  • Both were spotted in the wild in December 2024
  • Federal agencies have until February 3, 2025 to resolve the issues

The US Cybersecurity and Infrastructure Security Agency (CISA) has added two recently discovered BeyondTrust bugs to its Known Exploited Vulnerabilities (KEV) catalog.

The move means that CISA has seen evidence that the bugs are being exploited in the wild, and so has given federal agencies a deadline to patch the software or stop using it completely.