CVE-2026-48558 bypasses the OIDC token check in SimpleHelp, a remote support tool. Arctic Wolf is seeing active exploitation with a credential stealer. CISA gave federal agencies until 2 July.
- CVE-2026-48558: OIDC token auth bypass in SimpleHelp RMM - access without valid credentials; in CISA KEV, deadline 2 July.
- Arctic Wolf is observing active exploitation with custom malware for credential theft; ~1,000 of ~14,000 exposed servers are vulnerable.
- Lesson: RMM/VPN/jump host are a front line - patch right away, don't let authentication hang on one token, watch the access.
Plainly: a vulnerability in SimpleHelp - a tool for remotely managing other people's machines - made CISA's list of actively exploited holes. What matters isn't the score. What matters is what a tool like this opens up once it's breached.
Remote access tools are the juiciest target. By design, they keep their hands on many other people's machines at once. Breach the RMM-managed fleet and you haven't breached one machine - you've breached all of them behind it. The danger is measured by reach: how many clients hang off that one server.
Every remote access tool - RMM, VPN, jump host (a bridge server for remote access) - is a front line, not a back door. Patch it right away. Keep it behind authentication that doesn't hang on a single token. And watch who's coming through it - you, or someone pretending to be you.