SimpleHelp remote management software privileged technician account creation security flaw (CVE-2026-48558)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-48558 is a critical authentication bypass in SimpleHelp RMM that affects OIDC authentication and can let an unauthenticated attacker forge a token and obtain a trusted technician session on an internet-facing SimpleHelp server. In active exploitation, an attacker abused SimpleHelp’s own file-transfer and remote-execution features to deploy TaskWeaver and Djinn Stealer, turning the platform’s support channel into a malware-delivery path. SimpleHelp patched the flaw in versions 5.5.16 and 6.0 RC2, and CISA added the CVE to KEV on June 29.
Related Happenings
TaskWeaver and Djinn Stealer delivered through abused SimpleHelp RMM tools
Malware Activity
H score36
First: 30.06.2026 18:34
Last: 30.06.2026 18:34
Sources 1
How related:
The attacker then used the platform's own tools to push malware its researchers named TaskWeaver and Djinn Stealer.
About this happening:
The abuse of SimpleHelp RMM turned a trusted support channel into a malware delivery path for TaskWeaver and Djinn Stealer, expanding attacker reach into managed netwo...
TaskWeaver and Djinn Stealer delivered through abused SimpleHelp RMM tools
Malware ActivityHow related: The attacker then used the platform's own tools to push malware its researchers named TaskWeaver and Djinn Stealer.
About this happening: The abuse of SimpleHelp RMM turned a trusted support channel into a malware delivery path for TaskWeaver and Djinn Stealer, expanding attacker reach into managed netwo...
TaskWeaver and Djinn Stealer delivered through exploited SimpleHelp servers
Malware Activity
H score36
First: 30.06.2026 14:18
Last: 30.06.2026 14:18
Sources 1
How related:
"TaskWeaver is a heavily obfuscated Node.js loader, delivered as jquery.js and executed through node.exe, that implements an encrypted, reusable payload delivery channel rather than a fixed set of post exploitation commands," Blackpoint Cyber said in an analysis. "The observed second stage payload, Djinn Stealer, targets Windows, macOS, and Linux systems."
About this happening:
A SimpleHelp exploitation chain is now delivering TaskWeaver and Djinn Stealer, creating a direct path from server-side access to credential theft on managed endpo...
TaskWeaver and Djinn Stealer delivered through exploited SimpleHelp servers
Malware ActivityHow related: "TaskWeaver is a heavily obfuscated Node.js loader, delivered as jquery.js and executed through node.exe, that implements an encrypted, reusable payload delivery channel rather than a fixed set of post exploitation commands," Blackpoint Cyber said in an analysis. "The observed second stage payload, Djinn Stealer, targets Windows, macOS, and Linux systems."
About this happening: A SimpleHelp exploitation chain is now delivering TaskWeaver and Djinn Stealer, creating a direct path from server-side access to credential theft on managed endpo...
TaskWeaver and Djinn Stealer malware delivery via abused SimpleHelp technician access
Malware Activity
H score36
First: 30.06.2026 11:43
Last: 30.06.2026 11:43
Sources 1
How related:
In an attack observed by Blackpoint, a threat actor abused this access to deploy two malware families: TaskWeaver, a Node.js loader, and Djinn Stealer, a cross-platform information stealer.
About this happening:
An abused SimpleHelp technician session led to the delivery of TaskWeaver and Djinn Stealer, turning an access flaw into malware execution on managed systems and d...
TaskWeaver and Djinn Stealer malware delivery via abused SimpleHelp technician access
Malware ActivityHow related: In an attack observed by Blackpoint, a threat actor abused this access to deploy two malware families: TaskWeaver, a Node.js loader, and Djinn Stealer, a cross-platform information stealer.
About this happening: An abused SimpleHelp technician session led to the delivery of TaskWeaver and Djinn Stealer, turning an access flaw into malware execution on managed systems and d...
Storm-1175 high-tempo Medusa ransomware campaign
Campaign
H score59
First: 07.04.2026 13:02
Last: 07.04.2026 13:02
Sources 1
About this happening:
Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...
Storm-1175 high-tempo Medusa ransomware campaign
CampaignAbout this happening: Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...
Storm-1175 high-velocity zero-day and N-day intrusion campaign
Campaign
H score44
First: 07.04.2026 09:35
Last: 07.04.2026 09:35
Sources 1
About this happening:
Storm-1175 is running a high-velocity intrusion campaign that chains zero-day and N-day vulnerabilities to gain initial access to exposed systems, raising the risk...
Storm-1175 high-velocity zero-day and N-day intrusion campaign
CampaignAbout this happening: Storm-1175 is running a high-velocity intrusion campaign that chains zero-day and N-day vulnerabilities to gain initial access to exposed systems, raising the risk...
Timeline
-
15.06.2026 23:06 5 articles · 1mo ago
SimpleHelp releases fixes for CVE-2026-48558
Mitigation Patch UpdateSimpleHelp released versions 5.5.16 and 6.0RC2 to fix CVE-2026-48558, a critical flaw in the SimpleHelp remote management software that affected 5.5.15 and older and 6.0 pre-release versions. Organizations unable to update were advised to restrict technician login sources using IP-based allowlists.
Show sources
- SimpleHelp bug lets hackers create rogue remote support accounts — www.bleepingcomputer.com — 15.06.2026 23:06
- Critical SimpleHelp flaw exploited to deploy new stealer malware — www.bleepingcomputer.com — 29.06.2026 17:00
- Critical SimpleHelp Vulnerability Exploited for Malware Delivery — www.securityweek.com — 30.06.2026 11:43
- Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer — thehackernews.com — 30.06.2026 14:18
- Critical SimpleHelp Vulnerability Exploited For Malware Delivery — www.infosecurity-magazine.com — 30.06.2026 18:34
-
15.06.2026 23:06 2 articles · 1mo ago
Horizon3.ai details a SimpleHelp OIDC flaw that creates privileged Technician accounts
Initial DisclosureHorizon3.ai described CVE-2026-48558 in SimpleHelp remote management software as a critical issue that lets unauthenticated attackers create and log in as privileged Technician users when OIDC authentication is enabled, bypassing MFA. The flaw affects SimpleHelp 5.5.15 and older and 6.0 pre-release versions, and the researchers said there was no evidence of active exploitation.
Show sources
- SimpleHelp bug lets hackers create rogue remote support accounts — www.bleepingcomputer.com — 15.06.2026 23:06
- SimpleHelp bug lets hackers create rogue remote support accounts — www.bleepingcomputer.com — 15.06.2026 23:06