securityonline.info 6/30/2026, 2:30:44 AM · external

SimpleHelp Authentication Bypass Exploited in the Wild to Deploy TaskWeaver and Djinn Stealer

SimpleHelp Authentication Bypass Exploited in the Wild to Deploy TaskWeaver and Djinn Stealer
Developing story vulnerability 4 articles tracked
SimpleHelp authentication bypass (CVE-2026-48558) exploited to deploy malware
CyberSIXT Evidence Panel
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available

CVE- 2026-48558 is a critical authentication bypass vulnerability in SimpleHelp, affecting versions 5.5.0 and 6.0. Attackers exploit this flaw, which allows unauthenticated access to technician sessions by forging identity tokens. Blackpoint confirmed active exploitation in the wild, leading to the deployment of malware such as TaskWeaver and Djinn Stealer, which steal sensitive credentials. The CVSS score for this vulnerability is 10.0, indicating its severity.

SimpleHelp has released patches in versions 5.5.16 and 6.0 RC2, and users are urged to update immediately. Organizations are also advised to restrict access and monitor system logs for suspicious activity.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline