CVE Tools

Critical SimpleHelp Vulnerability Exploited for Malware Delivery

SecurityWeekBy Ionut Arghire

Reported exploitedSimpleHelp

Our summary

A critical authentication bypass in SimpleHelp remote monitoring and management (RMM) software has been used to deliver malware, tracked as CVE-2026-48558 (CVSS 10). The flaw impacts SimpleHelp’s OpenID Connect (OIDC) login flow by letting attackers supply forged identity tokens to obtain fully authenticated technician sessions, enabling remote file transfer and command execution over systems managed by the server. Observed intrusions deployed TaskWeaver and Djinn Stealer, while SimpleHelp addressed the issue in versions 5.5.16 and 6.0 RC2; CISA also added CVE-2026-48558 to its KEV catalog to prompt rapid patching.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store