Vulnerabilities · 76 days ago

Forged Technician Logins Put RMM Fleets at Risk

A SimpleHelp server is not just a host to patch. If an attacker can forge the OIDC technician login, they get the same trusted admin channel MSPs use to reach every managed endpoint, and that turns one compromise into fleet-wide malware delivery and credential theft.

Blackpoint’s report shows that abuse in the wild already moved from access to payload delivery. Attackers used the stolen technician session to push TaskWeaver and Djinn Stealer through SimpleHelp’s own file-transfer and remote-execution tools, and Djinn is built to harvest cloud, source-control, package-registry, SSH, and AI development-assistant credentials. CISA has now added CVE-2026-48558 to KEV, with a 2026-07-02 deadline, and SimpleHelp fixed the flaw in 5.5.16 and 6.0 RC2.

The forward risk is downstream. If technicians manage developer or cloud accounts from the same environment, stolen tokens can outlast the patched server and carry the compromise into codebases, registries, and cloud control planes.

CVE-2026-48558

NVD KEV

Known exploited · CISA KEV

CVSS 10 CRITICAL: simpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. EPSS 64% (99th percentile).

CISA federal remediation date Jul 2

Timeline

Sources

7 sources covering this story

Entities

Part of the PlainSec briefing for 2026-06-29

Editions

Related stories