CVE Tools

SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558)

Help Net SecurityBy Zeljka Zorz

Reported exploitedSimpleHelp RMM

Our summary

Attackers are actively exploiting CVE-2026-48558, a newly fixed authentication bypass in SimpleHelp RMM, to gain access and deploy Djinn Stealer on compromised systems. The malware is reported to target Windows, macOS, and Linux and can harvest credentials and sensitive data from many cloud platforms, development tools, browsers, SSH, and cryptocurrency wallets. This matters because stolen tokens, keys, and session data could enable re-entry and further compromise even after the original SimpleHelp server is isolated.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store