Why Privileged Access Management Tools Must Be Designed to a Higher Security Standard Than the Systems They Protect

When a Privileged Access Management platform is the target, the blast radius is everything behind it. CVE-2026-1731, a CVSS 9.9 pre-authentication OS command injection in BeyondTrust Remote Support, went from public PoC to confirmed in-the-wild exploitation in under 24 hours — exposing 8,500+ unpatched on-premises instances. This article dissects the PAM Platform Paradox and what it demands from product security architecture.