logo

Critical SimpleHelp Vulnerability Exploited for Malware Delivery

ID: a1e924b1-eeac-5fc2-a09d-5c92301dbadc

STIX ID: report--a1e924b1-eeac-5fc2-a09d-5c92301dbadc

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-06-30

Date Updated: 2026-07-02

...
...

### Executive Summary A critical authentication-bypass vulnerability (CVE-2026-48558) in SimpleHelp RMM has been exploited in the wild to deploy a Node.js loader called TaskWeaver that subsequently installed the Djinn Stealer infostealer, targeting sensitive credentials across Windows, macOS, and Linux; the flaw was patched in early June 2026 and added to CISA's Known Exploited Vulnerabilities catalog after confirmed exploitation, with organizations urged to apply patches and rotate exposed credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.