we_are_coded.by CODE · The world, decoded
БГ
CISA

A critical hole in SimpleHelp lets an attacker in without a password - and it's already being used in attacks

CISASecurity

CVE-2026-48558 bypasses the OIDC token check in SimpleHelp, a remote support tool. Arctic Wolf is seeing active exploitation with a credential stealer. CISA gave federal agencies until 2 July.

In short
  • CVE-2026-48558: OIDC token auth bypass in SimpleHelp RMM - access without valid credentials; in CISA KEV, deadline 2 July.
  • Arctic Wolf is observing active exploitation with custom malware for credential theft; ~1,000 of ~14,000 exposed servers are vulnerable.
  • Lesson: RMM/VPN/jump host are a front line - patch right away, don't let authentication hang on one token, watch the access.
Checked on6 July 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

Plainly: a vulnerability in SimpleHelp - a tool for remotely managing other people's machines - made CISA's list of actively exploited holes. What matters isn't the score. What matters is what a tool like this opens up once it's breached.

The facts: CVE-2026-48558 is a bypass of the OIDC token signature check (a standard protocol for account sign-in) in SimpleHelp RMM - a remote attacker with no valid credentials can create a session for themselves. Arctic Wolf (a cybersecurity firm) reports active exploitation in real attacks, with custom malware for stealing access credentials and maintaining persistence in the managed environments. CISA added the vulnerability to its catalog of actively exploited flaws and gave federal agencies until 2 July. Affected are versions 5.5.x below 5.5.16 and the 6.0 pre-release; the patch is in 5.5.16. According to internet scanning, about 1,000 of nearly 14,000 exposed servers are vulnerable. Primary source: CISA KEV / Arctic Wolf.

Remote access tools are the juiciest target. By design, they keep their hands on many other people's machines at once. Breach the RMM-managed fleet and you haven't breached one machine - you've breached all of them behind it. The danger is measured by reach: how many clients hang off that one server.

Every remote access tool - RMM, VPN, jump host (a bridge server for remote access) - is a front line, not a back door. Patch it right away. Keep it behind authentication that doesn't hang on a single token. And watch who's coming through it - you, or someone pretending to be you.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→CISA - Known Exploited Vulnerabilities Catalog→Arctic Wolf - CVE-2026-48558 SimpleHelp RMM
Original: https://wearecoded.com/en/articles/simplehelp-rmm-auth-bypass-kev-48558.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news