securityaffairs.com 6/30/2026, 8:11:54 PM · external

U.S. CISA adds SimpleHelp flaw to its Known Exploited Vulnerabilities catalog

U.S. CISA adds SimpleHelp flaw to its Known Exploited Vulnerabilities catalog
Developing story vulnerability 9 articles tracked
SimpleHelp authentication bypass (CVE-2026-48558) exploited to deploy TaskWeaver and Djinn Stealer
CyberSIXT Evidence Panel
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available

THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical authentication bypass vulnerability, tracked as CVE-2026-48558, to its Known Exploited Vulnerabilities catalog. This flaw affects SimpleHelp versions 5.5.15 and earlier, as well as 6.0 pre-release versions, allowing attackers to forge authentication tokens and gain unauthorized access to technician sessions.

Discovered by Zach Hanley from Horizon3.ai, the vulnerability poses significant risks to organizations using SimpleHelp for remote support and can potentially allow lateral movement within networks. CISA has mandated that federal agencies address this vulnerability by July 2, 2026, recommending that private organizations also review and mitigate the风险.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline