CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 64

As cited

Copy frozen at (site build).

vulnerabilities

Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer

Attackers are exploiting CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp's OpenID Connect (OIDC) implementation, to deliver two newly identified malware families called TaskWeaver and Djinn Stealer. The vulnerability has a CVSS score of 10.0 and allows unauthenticated access to affected systems.

Why it matters: SimpleHelp users running unpatched systems face immediate risk of malware deployment; patching should be prioritized if available.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer

Attackers are actively exploiting CVE-2026-48558, a critical authentication bypass flaw in SimpleHelp, to install two previously unknown malware variants called TaskWeaver and Djinn Stealer. The vulnerability affects the OpenID Connect flow and allows unauthenticated access to the system.

Why it matters: Organizations running SimpleHelp must patch immediately, as this vulnerability is under active exploitation and enables remote code execution and credential theft on affected systems.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer

Attackers are actively exploiting CVE-2026-48558, a critical authentication bypass flaw in SimpleHelp, to install two previously unknown malware variants called TaskWeaver and Djinn Stealer. The vulnerability affects the OpenID Connect flow and allows unauthenticated access to the system.

Why it matters: Organizations running SimpleHelp must patch immediately, as this vulnerability is under active exploitation and enables remote code execution and credential theft on affected systems.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary