DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 13:15:29ZSOURCES: 14CRITICAL: 18
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — wp2shell (CVE-2026-63030 + CVE-2026-60137) is being actively exploited in the wild —… /// @MsftSecIntel CRITICAL — Microsoft is tracking active exploitation of CVE-2026-63030 and CVE-2026-60137… /// @vxunderground CRITICAL — wp2shell PoCs are now floating around the internet. Public exploit code for the full… /// @FalconFeedsio CRITICAL — 🔴 Qilin ransomware group has now publicly claimed 2,035+ victims on its dark web leak… /// @TalosSecurity CRITICAL — Talos is tracking mass exploitation of wp2shell (CVE-2026-63030/CVE-2026-60137).…
18Critical Threats
18Active CVEs
10IOCs Tracked
6New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-48558PUBLISHED: 2026-06-05
CRITICALCVE-2026-48558★ CISA KEV LISTED

SimpleHelp RMM OIDC Authentication Bypass

VENDOR: SimpleHelp//PRODUCT: SimpleHelp RMM
10
CRITICAL
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
LIMITED EXPLOITATION

SimpleHelp fails to verify the cryptographic signature of OIDC identity tokens when generic OIDC or Azure AD OIDC authentication is configured with group-authenticated logins enabled. An unauthenticated attacker can forge a token to obtain a fully authenticated 'Technician' session — bypassing MFA on first login — and then remotely access all managed endpoints, execute scripts, and pivot across the entire MSP customer base. Confirmed in-the-wild exploitation by an unknown threat actor has delivered two novel malware families: TaskWeaver (an obfuscated Node.js loader) and Djinn Stealer (a cross-platform credential/cloud-token harvester targeting Windows, macOS, and Linux). CISA added to KEV on June 29, 2026.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
NONE
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONSSimpleHelp versions 5.5.15 and earlier; 6.0 pre-release versions (fixed in 5.5.16 and 6.0 RC2)
  • https://thehackernews.com/2026/06/attackers-exploit-simplehelp-cve-2026.html
  • https://horizon3.ai/attack-research/disclosures/cve-2026-48558-simplehelp-authentication-bypass-iocs/
  • https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  • https://hard2bit.com/en/blog/cve-2026-48558-simplehelp-oidc-bypass-taskweaver-djinn-stealer/
SHARE BRIEF:✕ Post on Xin Share on LinkedIn