Critical SimpleHelp Vulnerability Exploited for Malware Delivery
ID: a1e924b1-eeac-5fc2-a09d-5c92301dbadc
STIX ID: report--a1e924b1-eeac-5fc2-a09d-5c92301dbadc
Feed Name: ThreatCluster
### Executive Summary A critical authentication-bypass vulnerability (CVE-2026-48558) in SimpleHelp RMM has been exploited in the wild to deploy a Node.js loader called TaskWeaver that subsequently installed the Djinn Stealer infostealer, targeting sensitive credentials across Windows, macOS, and Linux; the flaw was patched in early June 2026 and added to CISA's Known Exploited Vulnerabilities catalog after confirmed exploitation, with organizations urged to apply patches and rotate exposed credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
