CISA Adds SimpleHelp Authentication Bypass Vulnerability to KEV Catalog
CISA has added CVE-2026-48558, a SimpleHelp authentication bypass vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog, citing active exploitation.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially added CVE-2026-48558, a critical authentication bypass vulnerability affecting SimpleHelp software, to its Known Exploited Vulnerabilities (KEV) Catalog. This designation signifies that the vulnerability has been observed under active exploitation in the wild, posing a significant and immediate threat to organizations.
The vulnerability, identified as a SimpleHelp Authentication Bypass Vulnerability, allows malicious actors to circumvent authentication mechanisms. While specific technical details of the bypass are not elaborated in the announcement, such flaws typically enable unauthorized access to systems or sensitive data that would otherwise be protected. The inclusion in the KEV Catalog underscores the severity and widespread risk associated with this particular flaw.
Federal Civilian Executive Branch (FCEB) agencies are now mandated to prioritize the remediation of CVE-2026-48558 on any publicly exposed assets. This directive stems from Binding Operational Directive (BOD) 26-04, which establishes stringent vulnerability management requirements for federal agencies. The BOD emphasizes the critical role of the KEV Catalog in identifying high-risk vulnerabilities that demand immediate attention, particularly those that grant complete control of an asset post-exploitation.
BOD 26-04 requires federal agencies to implement a risk-based approach to vulnerability management, focusing on rapid remediation of identified KEV Catalog entries. The directive also outlines expectations for agencies regarding the detection of potential compromises that may have occurred before a patch was applied. This proactive stance aims to minimize the window of opportunity for attackers to exploit known weaknesses.
While BOD 26-04 specifically targets FCEB agencies, CISA strongly encourages all organizations, including those in the private sector, to adopt similar risk-based vulnerability management practices. Prioritizing the patching of vulnerabilities listed in the KEV Catalog is a crucial step in bolstering an organization's overall cybersecurity posture and defending against prevalent attack vectors.
CISA maintains the KEV Catalog as a dynamic resource, continuously adding vulnerabilities that meet its criteria for active exploitation and significant risk. The agency also provides a nomination form for the public to submit vulnerabilities they are aware of that are being exploited but are not yet listed. To be considered for the KEV Catalog, a vulnerability must possess a CVE ID, demonstrable evidence of exploitation, and clear mitigation guidance.
The addition of CVE-2026-48558 to the KEV Catalog serves as a stark reminder of the persistent threat landscape and the importance of timely vulnerability management. Organizations are urged to review their SimpleHelp deployments and apply necessary security updates to mitigate the risk of exploitation.
The Djinn infostealer is actively exploiting CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp. This new report details how Djinn leverages this flaw to target credentials for cloud and AI services, impacting development and administrative environments and potentially granting access to wider enterprise systems.
The new article details the specific malware families, TaskWeaver and Djinn Stealer, deployed by threat actors exploiting CVE-2026-48558. Djinn Stealer is noted for its focus on exfiltrating developer-specific secrets, including credentials for AI development tools, providing attackers with a deeper foothold into development pipelines.
This new report details how threat actors are actively exploiting CVE-2026-48558, an authentication bypass vulnerability in SimpleHelp RMM, to deploy the Djinn Stealer malware. The malware is designed to exfiltrate a wide range of sensitive credentials from Windows, macOS, and Linux systems, including those for cloud platforms, source control, and cryptocurrency wallets. Attackers leverage the RMM platform for a trusted execution path, making their activity appear as an authorized support session.
This new report details the specific malware families, TaskWeaver and Djinn Stealer, deployed by attackers exploiting CVE-2026-48558. TaskWeaver acts as an obfuscated loader for Djinn Stealer, which is designed to harvest credentials from cloud platforms, source control, AI development assistants, and cryptocurrency wallets across Windows, macOS, and Linux systems.
This new report details the specific malware deployed following the exploitation of CVE-2026-48558, identifying a new loader named TaskWeaver and an information-stealer called Djinn Stealer. TaskWeaver is an obfuscated Node.js loader that establishes encrypted C2 communication and dynamically fetches payloads, while Djinn Stealer targets a wide array of credentials, including cloud services, developer tokens, and AI tool access. The article also provides detailed indicators of compromise (IoCs) and recommends immediate patching and credential rotation.
This new analysis details the specific malware families, TaskWeaver and Djinn Stealer, deployed by threat actors exploiting the SimpleHelp authentication bypass vulnerability (CVE-2026-48558). The attackers leveraged the RMM software's own file-transfer and remote-execution features to push these previously undocumented malware strains, which included a modular Node.js loader and a cross-platform infostealer capable of harvesting sensitive credentials and tokens.
The new article provides further technical details on the exploitation of CVE-2026-48558, specifically noting that the vulnerability arises from improper validation of identity tokens when SimpleHelp is configured with OpenID Connect (OIDC) authentication. It highlights that the application accepts tokens without verifying their cryptographic signature, allowing attackers to forge tokens and bypass multi-factor authentication (MFA) to gain full technician session access.
The article confirms that the SimpleHelp vulnerability, CVE-2026-48558, is being actively exploited in the wild. Attackers are leveraging this authentication bypass flaw to deploy the novel Djinn Stealer malware, which targets credentials across various platforms including cloud services, development tools, and cryptocurrency wallets on Windows, macOS, and Linux systems.