Attackers are actively exploiting CVE-2026-48558, a maximum-severity authentication bypass in SimpleHelp RMM, to forge OpenID Connect identity tokens and obtain fully authenticated technician sessions on exposed servers. The flaw affects deployments using generic OIDC or Azure AD OIDC because SimpleHelp accepted identity tokens without validating their cryptographic signatures, enabling unauthenticated access and, in some cases, bypass of MFA during technician enrollment. The issue affects SimpleHelp 5.5.1 through 5.5.15 and 6.0 pre-release builds before 6.0 RC2, and has been patched in 5.5.16+ and 6.0 RC2+.
In observed intrusions, attackers abused the trusted RMM channel to transfer files and execute commands across managed endpoints, deploying the obfuscated TaskWeaver Node.js loader followed by the newly identified Djinn Stealer malware. Reporting says TaskWeaver fetched additional payloads and used encrypted communications, while Djinn Stealer harvested credentials and sensitive data from browsers, cloud platforms, developer and package registry tooling, SSH environments, AI tools, and cryptocurrency wallets across Windows, macOS, and Linux before exfiltration. CISA added the flaw to its Known Exploited Vulnerabilities catalog, and sector alerts warned that compromise of a SimpleHelp server could give attackers downstream access across MSP and utility environments, increasing the risk of lateral movement, credential theft, and ransomware deployment.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
In the KEV entry, CISA ordered federal civilian executive branch agencies to remediate CVE-2026-48558 by the stated due date.
By emulating the TaskWeaver loader, Blackpoint retrieved the follow-on Djinn Stealer malware and documented its cross-platform credential and data theft behavior along with its exfiltration methods.
SimpleHelp made fixes available for the vulnerability in version 5.5.16 and in 6.0 RC2 or later, addressing the OIDC authentication bypass affecting earlier releases.
Blackpoint Cyber reported active exploitation of CVE-2026-48558 on internet-facing SimpleHelp servers, where attackers gained technician sessions and used the trusted RMM channel to push the TaskWeaver loader and Djinn Stealer to managed systems.
CISA added the SimpleHelp authentication bypass vulnerability to its Known Exploited Vulnerabilities catalog, formally recognizing active exploitation and directing agencies to apply mitigations under BOD 26-04.
Horizon3.ai publicly disclosed CVE-2026-48558, an authentication bypass flaw in SimpleHelp's OIDC flow that allows forged identity tokens to be accepted without signature verification.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
7 references tracked. Mallory keeps watching after this page renders.
waterisac.org
Open sourcescworld.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcesocradar.io
Open sourcehelpnetsecurity.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.