Critical SimpleHelp Vulnerability Exploited for Malware Delivery

https://www.securityweek.com/wp-content/uploads/2025/11/malware.jpeg

A recent authentication bypass vulnerability in the SimpleHelp remote monitoring and management (RMM) software has been exploited for malware delivery.

Tracked as CVE-2026-48558 (CVSS score of 10), the bug impacts SimpleHelp’s OpenID Connect (OIDC) authentication flow and allows a remote attacker to obtain a fully authenticated technician session.

The issue exists because, when OIDC authentication is configured, the application does not verify the cryptographic signature of identity tokens, allowing an unauthenticated attacker to submit a forged token during login.

By accessing an internet-facing SimpleHelp server, an attacker can transfer files and execute commands on all systems managed through the server.

In an attack observed by Blackpoint, a threat actor abused this access to deploy two malware families: TaskWeaver, a Node.js loader, and Djinn Stealer, a cross-platform information stealer.

TaskWeaver was used to perform system fingerprinting and to deploy a JavaScript payload that was executed with full Node.js access. The...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more