CVE-2026-48558 in SimpleHelp: how a single auth bypass opened the door to data theft

Colleagues, I want to draw your attention to a cybersecurity development: CVE-2026-48558 in SimpleHelp is already being exploited.
What stands out is the attack chain: OIDC-based authentication bypass, Technician session takeover, and subsequent deployment of TaskWeaver and Djinn Stealer.
According to researchers, the malware targets Windows, macOS, and Linux. Its main objectives are credentials, cloud services, code repositories, SSH, AI tools, and crypto wallets. CISA has already added the flaw to KEV.
Why this matters: one compromise of an RMM platform can expose the entire managed environment. What would you check first — RMM, OIDC, or Technician privileges?
#cybersecurity #RMM #vulnerabilities #CISA

