SimpleHelp CVE-2026-48558 CVSS 10.0 auth bypass actively exploited, CISA July 2 deadline
If your IT runs through SimpleHelp remote management software, intruders can log in as a full admin. A CVSS 10.0 auth-bypass flaw (CVE-2026-48558) lets attackers forge a privileged Technician account and skip MFA. CISA set a July 2 patch deadline. Per Arctic Wolf and CISA.
https://arcticwolf.com/resources/blog/cve-2026-48558-critical-authentication-bypass-vulnerability-in-simplehelp-rmm-exploited-for-credential-theft-and-malware-delivery/
Published on
BlueskyXThreadsFacebook