The critical vulnerability CVE-2026-48558 in the remote administration software SimpleHelp is being actively exploited by unknown threat actors, who are deploying two new, previously unknown malware families: TaskWeaver loader and Djinn Stealer . CVE-2026-48558 has received the maximum CVSS severity score of 10.0 , making it one of the most dangerous vulnerabilities disclosed this year. CISA has already added the vulnerability to the Known Exploited Vulnerabilities list , asking federal agencies to remediate the issue by July 7, 2026 .
See also: SimpleHelp: Vulnerability allows creation of remote support accounts

The vulnerability affects SimpleHelp 's OpenID Connect (OIDC) authentication flow and allows an unauthorized attacker to submit a fake token that is accepted as valid, thereby obtaining a fully authenticated Technician session . The vulnerability was publicly disclosed by Horizon3.ai on June 12, 2026 , when security researcher Zach Hanley explained that it affects servers using either generic OIDC or Azure AD OIDC . Of particular concern is that even if the SimpleHelp server is configured to enforce MFA for technicians, an attacker can bypass this mechanism, as technicians can register their own MFA method upon first login . At the time of disclosure, approximately 1,000 exposed SimpleHelp servers online were running the vulnerable configuration. Regarding CVE-2026-48558 ,
According to research by Blackpoint Cyber and researchers Nevan Beal and Sam Decker, a successful exploitation of CVE-2026-48558 allowed the threat actor to gain a certified Technician session on a publicly accessible server. The compromised RMM provided the attacker with a trusted administrative channel capable of transferring files and executing commands to all systems managed by the server — essentially, the attacker “logged in as a trusted technician” and gained access to the entire infrastructure.
CVE-2026-48558 and the TaskWeaver Loader: How the attack works
TaskWeaver is a heavily obfuscated loader written in Node.js , delivered disguised as a 1.08 MB jquery.js file from a temporary URL hosted on Cloudflare , and executed via node.exe . Rather than containing a fixed set of post-exploitation commands, TaskWeaver implements an encrypted, reusable payload delivery channel. Specifically, it fingerprints the system , establishes encrypted communication with a remote server, and retrieves additional JavaScript modules with elevated access privileges to the Node.js runtime . The second payload stage observed is Djinn Stealer , which shares the same obfuscation framework as TaskWeaver and embeds the same RSA public key , strongly linking the two samples.
See also: Flaws in SimpleHelp Remote Access Software Allow Hacks
Djinn Stealer is a cross-platform infostealer that targets Windows, macOS , and Linux, designed to harvest credentials from an impressively wide range of services. Its targets include cloud platforms such as AWS, Azure, Google Cloud, Oracle Cloud Infrastructure, Cloudflare , and DigitalOcean, as well as infrastructure tools such as Docker, Terraform, HashiCorp Vault , and Kubernetes Helm. It also targets package registries such as npm, PyPI, NuGet, Cargo , and Maven, as well as AI development tools such as Anthropic Claude, Google Gemini, OpenAI Codex , and Cline. Finally, it harvests data from cryptocurrency wallets (Bitcoin, Ethereum, Monero, Exodus , and others), browsers, SSH keys, and source control credentials. On Linux, the malware also attempts to read the /proc/ and /proc/, which may contain sensitive information about running processes. In relation to CVE-2026-48558,
CVE-2026-48558: What organizations using SimpleHelp should do
Organizations using SimpleHelp with OIDC authentication should take immediate action. The first and foremost step is to immediately apply the security update for CVE-2026-48558 according to the manufacturer’s instructions. In addition, it is recommended to assume that a breach has already occurred if servers were exposed to the internet, and to check logs for suspicious Technician sessions. Security teams should look for signs of TaskWeaver and Djinn Stealer, including obfuscated JavaScript payloads, suspicious node.exe , and files with legitimate library names such as jquery.js. It is also necessary to immediately rotate credentials for cloud, SSH, source control, package registries, and AI development tools.

See also: SimpleHelp and ScreenConnect misused for phishing attacks
This attack is a prime example of why RMM tools are particularly attractive targets for cybercriminals: a single server compromise can give access to dozens or hundreds of managed systems. The fact that Djinn Stealer specifically targets developer and cloud infrastructure credentials suggests that attackers are seeking access to supply chain and cloud environments, with potentially devastating consequences. According to The Hacker News, this campaign follows a broader trend of actively exploiting critical vulnerabilities in remote management software shortly after they are publicly disclosed, making it imperative to apply security patches immediately.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
