As cited
Copy frozen at (site build).
vulnerabilities
Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer
Attackers are exploiting CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp's OpenID Connect (OIDC) implementation, to deliver two newly identified malware families called TaskWeaver and Djinn Stealer. The vulnerability has a CVSS score of 10.0 and allows unauthenticated access to affected systems.
Why it matters: SimpleHelp users running unpatched systems face immediate risk of malware deployment; patching should be prioritized if available.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer
Attackers are actively exploiting CVE-2026-48558, a critical authentication bypass flaw in SimpleHelp, to install two previously unknown malware variants called TaskWeaver and Djinn Stealer. The vulnerability affects the OpenID Connect flow and allows unauthenticated access to the system.
Why it matters: Organizations running SimpleHelp must patch immediately, as this vulnerability is under active exploitation and enables remote code execution and credential theft on affected systems.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer
Attackers are actively exploiting CVE-2026-48558, a critical authentication bypass flaw in SimpleHelp, to install two previously unknown malware variants called TaskWeaver and Djinn Stealer. The vulnerability affects the OpenID Connect flow and allows unauthenticated access to the system.
Why it matters: Organizations running SimpleHelp must patch immediately, as this vulnerability is under active exploitation and enables remote code execution and credential theft on affected systems.
- Source published
- First seen by Cybersecurity Tracker