A critical flaw in SimpleHelp remote management software can let an outsider create a privileged support account on vulnerable servers. The bug, CVE-2026-48558, affects SimpleHelp 5.5.15 and earlier plus 6.0 pre-release builds when OpenID Connect (OIDC) login is enabled and certain technician-group settings are in use. An unauthenticated attacker can bypass normal identity checks and multi-factor authentication to gain technician access; fixes are in 5.5.16 and 6.0RC2.
Arctic Wolf Labs
2026.06.30
95% relevant
This source updates the same CVE-2026-48558 event with exploitation details: attackers are abusing the OIDC token-signature validation flaw to bypass MFA, gain technician-level access, steal credentials, and deploy custom malware. It also adds exposure estimates of about 14,000 internet-facing servers and roughly 1,000 directly vulnerable systems, plus CISA KEV urgency and mitigation guidance.
info@thehackernews.com (The Hacker News)
2026.06.30
95% relevant
This article advances the same underlying event by showing that CVE-2026-48558 is not just a disclosed flaw but is being actively exploited to create unauthorized access and deploy TaskWeaver and Djinn Stealer on victim systems.
Ionut Arghire
2026.06.30
96% relevant
This updates the same underlying CVE-2026-48558 SimpleHelp event by adding post-disclosure exploitation details: attackers used the auth-bypass flaw to obtain technician sessions and deploy TaskWeaver and Djinn Stealer, and CISA has now added the flaw to the KEV catalog.
Bill Toulas
2026.06.15
100% relevant
This article establishes a new tracked story because it reports the disclosure and fix of CVE-2026-48558, a distinct SimpleHelp authentication flaw with no corresponding existing story in the tracker.