Find notable cyber news and cases, enriched with sources, timelines, and signals.

SimpleHelp remote management software privileged technician account creation security flaw (CVE-2026-48558)

Vulnerability
First reported
Last updated
Happening score
H score 46
4 unique sources, 5 articles

Summary

Hide ▲

CVE-2026-48558 is a critical authentication bypass in SimpleHelp RMM that affects OIDC authentication and can let an unauthenticated attacker forge a token and obtain a trusted technician session on an internet-facing SimpleHelp server. In active exploitation, an attacker abused SimpleHelp’s own file-transfer and remote-execution features to deploy TaskWeaver and Djinn Stealer, turning the platform’s support channel into a malware-delivery path. SimpleHelp patched the flaw in versions 5.5.16 and 6.0 RC2, and CISA added the CVE to KEV on June 29.

Related Happenings

TaskWeaver and Djinn Stealer delivered through abused SimpleHelp RMM tools

Malware Activity
H score36 First: 30.06.2026 18:34 Last: 30.06.2026 18:34 Sources 1

How related: The attacker then used the platform's own tools to push malware its researchers named TaskWeaver and Djinn Stealer.

About this happening: The abuse of SimpleHelp RMM turned a trusted support channel into a malware delivery path for TaskWeaver and Djinn Stealer, expanding attacker reach into managed netwo...

TaskWeaver and Djinn Stealer delivered through exploited SimpleHelp servers

Malware Activity
H score36 First: 30.06.2026 14:18 Last: 30.06.2026 14:18 Sources 1

How related: "TaskWeaver is a heavily obfuscated Node.js loader, delivered as jquery.js and executed through node.exe, that implements an encrypted, reusable payload delivery channel rather than a fixed set of post exploitation commands," Blackpoint Cyber said in an analysis. "The observed second stage payload, Djinn Stealer, targets Windows, macOS, and Linux systems."

About this happening: A SimpleHelp exploitation chain is now delivering TaskWeaver and Djinn Stealer, creating a direct path from server-side access to credential theft on managed endpo...

TaskWeaver and Djinn Stealer malware delivery via abused SimpleHelp technician access

Malware Activity
H score36 First: 30.06.2026 11:43 Last: 30.06.2026 11:43 Sources 1

How related: In an attack observed by Blackpoint, a threat actor abused this access to deploy two malware families: TaskWeaver, a Node.js loader, and Djinn Stealer, a cross-platform information stealer.

About this happening: An abused SimpleHelp technician session led to the delivery of TaskWeaver and Djinn Stealer, turning an access flaw into malware execution on managed systems and d...

Storm-1175 high-tempo Medusa ransomware campaign

Campaign
H score59 First: 07.04.2026 13:02 Last: 07.04.2026 13:02 Sources 1

About this happening: Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...

Storm-1175 high-velocity zero-day and N-day intrusion campaign

Campaign
H score44 First: 07.04.2026 09:35 Last: 07.04.2026 09:35 Sources 1

About this happening: Storm-1175 is running a high-velocity intrusion campaign that chains zero-day and N-day vulnerabilities to gain initial access to exposed systems, raising the risk...

Timeline

  1. 15.06.2026 23:06 5 articles · 1mo ago

    SimpleHelp releases fixes for CVE-2026-48558

    Mitigation Patch Update

    SimpleHelp released versions 5.5.16 and 6.0RC2 to fix CVE-2026-48558, a critical flaw in the SimpleHelp remote management software that affected 5.5.15 and older and 6.0 pre-release versions. Organizations unable to update were advised to restrict technician login sources using IP-based allowlists.

    Show sources
  2. 15.06.2026 23:06 2 articles · 1mo ago

    Horizon3.ai details a SimpleHelp OIDC flaw that creates privileged Technician accounts

    Initial Disclosure

    Horizon3.ai described CVE-2026-48558 in SimpleHelp remote management software as a critical issue that lets unauthenticated attackers create and log in as privileged Technician users when OIDC authentication is enabled, bypassing MFA. The flaw affects SimpleHelp 5.5.15 and older and 6.0 pre-release versions, and the researchers said there was no evidence of active exploitation.

    Show sources