U.S. CISA adds SimpleHelp flaw to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-57726 +1 in the same advisory: …57728 | Missing-Authorization Privilege Escalation in SimpleHelp Remote Support <= 5.5.7 SimpleHelp remote support software versions 5.5.7 and earlier contain a missing-authorization flaw (CWE-862) that lets low-privileged technicians create API keys with excessive permissions. A network attacker holding only a technician-level account can mint such an over-privileged API key and use it to escalate to the SimpleHelp server admin role, with no user interaction required (CVSS 3.1 score 9.9, scope changed). Successful exploitation yields full administrative control of the SimpleHelp server, the remote-access/RMM platform support staff use to reach endpoints, which can also expose downstream customer environments when the server is run by an MSP. Any organization running SimpleHelp 5.5.7 or earlier is affected, with MSPs at particular risk given their downstream reach. The flaw is confirmed exploited in the wild: it was added to CISA KEV on 2026-04-24 with known ransomware use, carries a 66.6% EPSS score (99th percentile), and public reporting describes ransomware operators chaining SimpleHelp flaws in double-extortion attacks against an MSP and its customers. Do: Upgrade SimpleHelp to the latest vendor release newer than 5.5.7 and apply vendor mitigation guidance; federal agencies must meet BOD 22-01 requirements or discontinue use. Audit existing API keys (especially those created by technician accounts) for excessive permissions, review audit logs for unexpected key creation or admin activity, and restrict internet exposure of SimpleHelp servers. Organizations whose MSP uses SimpleHelp should confirm the MSP's instance is patched before trusting remote sessions. | 9.9 group max | 67% | KEV ransomware |
| moderatelow thousands of exposed self-hosted SimpleHelp server deployments (est.), amplified to many downstream endpoints where instances are run by MSPs | |
| CVE-2026-48558 | Authentication Bypass via Forged OIDC Tokens in SimpleHelp CVE-2026-48558 is an authentication bypass (CWE-347, improper verification of cryptographic signature) in the SimpleHelp remote access/support platform's OpenID Connect (OIDC) login flow, where submitted identity tokens are accepted without verifying their signature. It is triggered when OIDC authentication is configured: a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims and obtain a fully authenticated technician session, and in some configurations this also bypasses multi-factor authentication. Related reporting describes a path from this bypass to remote code execution. Only SimpleHelp deployments using OIDC-based (e.g., SSO) authentication are affected; deployments relying on local SimpleHelp accounts are not described as affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-06-29, confirming exploitation in the wild, with a 30% EPSS probability of exploitation within 30 days and no public proof-of-concept known. Do: Update SimpleHelp to the latest release per vendor instructions, prioritizing any internet-facing server (CISA KEV listing means federal agencies must act under BOD 26-04). Until patched, restrict access to the SimpleHelp web login to trusted management networks (VPN/firewall) or temporarily switch from OIDC to local-account authentication with MFA. Verify whether OIDC is enabled on each instance and review technician login logs for sessions created with unusual or unexpected identity claims. | 9.5 | 64% | KEV |
| moderateseveral thousand vulnerable servers (subset of roughly 10,000 internet-exposed SimpleHelp instances, limited to those with OIDC configured) |
Full article596 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a SimpleHelp flaw to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a SimpleHelp flaw, tracked as CVE-2026-48558 (CVSS score v3.1 of 10.0), to its Known Exploited Vulnerabilities (KEV) catalog.
CVE-2026-48558 is a critical authentication bypass vulnerability in SimpleHelp versions 5.5.15 and earlier and 6.0 pre-release versions. When OIDC authentication is enabled, the software fails to verify the cryptographic signature of identity tokens, allowing a remote, unauthenticated attacker to forge a token and gain a fully authenticated technician session. In some configurations, the flaw can also bypass multi-factor authentication (MFA), with no user interaction required.
The researcher Zach Hanley (@hacks_zach) of Horizon3.ai discovered the vulnerability with the help of generative AI.
SimpleHelp is a remote support and remote access platform that organizations use to provide technical assistance, manage endpoints, and access computers over the internet. It is commonly deployed by IT departments, managed service providers (MSPs), and help desks to troubleshoot devices, transfer files, run remote commands, and perform system administration without being physically present.
Because SimpleHelp servers often provide privileged access to many customer systems, vulnerabilities in the platform can be particularly dangerous. If attackers compromise a SimpleHelp server, they may gain the same level of access as legitimate technicians, potentially allowing them to move laterally across networks, deploy malware, or steal sensitive data.
“The vulnerability identified affects servers configured to use either version of OIDC and is rooted in the way that SimpleHelp validates the IdP assertions. In many SimpleHelp deployments that have OIDC-type authentication enabled, an unauthenticated attacker can create and authenticate as a new “Technician” user. This Technician, by default, can perform privileged management activities such as remoting into managed endpoints, executing scripts, and more.” reads a technical analysis published by Hanley.
“Even when the SimpleHelp server is configured to enforce MFA for technicians, this issue allows the attacker to bypass this mechanism because on first login, technicians can self-register their own MFA method.”
The researcher pointed out that the flaw can be exploited only if OIDC authentication is enabled, an OIDC provider is linked to a TechnicianGroup, and the “Allow group authenticated logins” option is enabled. Researchers have withheld technical details but released indicators of compromise to help organizations detect potential exploitation.
BlackPoint researchers first observed attacks in the wild exploiting this vulnerability.
“The Adversary Pursuit Group identified two previously undiscovered malware samples, TaskWeaver and Djinn Stealer.” states the report published by BlackPoint. “The intrusion began with confirmed exploitation of CVE-2026-48558, allowing the attacker to bypass SimpleHelp OIDC authentication and obtain a technician session.”
Since January 2025, exposed SimpleHelp servers have risen from about 3,400 to nearly 14,000. Of those, around 7.2% were found configured with the vulnerable OIDC authentication method, according to the expert.
Hanley also published Indicators of Compromise (IoCs) for this attack.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the vulnerability by the end of this week, on July 2nd, 2026.
In April, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two other SimpleHelp flaws to the KeV Catalog:
- CVE-2024-57726 SimpleHelp Missing Authorization Vulnerability
- CVE-2024-57728 SimpleHelp Path Traversal Vulnerability
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/194503/security/u-s-cisa-adds-simplehelp-flaw-to-its-known-exploited-vulnerabilities-catalog.html