The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical authentication bypass vulnerability affecting SimpleHelp remote support software to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild.
The flaw, tracked as CVE-2026-48558, was added on June 29, 2026, with a remediation deadline of July 2, 2026, giving federal agencies and organizations using the product a tight three-day window to apply mitigations.
The vulnerability resides in SimpleHelp’s OpenID Connect (OIDC) authentication flow and is classified under CWE-347 (Improper Verification of Cryptographic Signature).
SimpleHelp Authentication Bypass Flaw
When OIDC authentication is configured, the application accepts identity tokens submitted during login without verifying their cryptographic signature.
This design flaw allows a remote, unauthenticated attacker to forge a token containing arbitrary identity claims, effectively tricking SimpleHelp into granting a fully authenticated technician session.
Given that technician sessions typically carry elevated privileges for remote access and system management, successful exploitation hands attackers significant control over targeted environments.
Perhaps more concerning, CISA notes that in certain configurations, this bypass technique can also circumvent multi-factor authentication (MFA) protections.
Since MFA is often relied upon as a critical last line of defense against credential-based attacks, its bypass here significantly raises the stakes for organizations that assumed MFA provided adequate protection against unauthorized access.
While CISA’s KEV entry lists the ransomware usage status as “Unknown,” the inclusion of this flaw in the catalog confirms it is being actively exploited in real-world attacks.
Remote support tools like SimpleHelp are historically attractive targets for threat actors because compromising them can provide a foothold into numerous downstream client networks, a pattern seen in previous incidents involving similar remote monitoring and management (RMM) platforms.
CISA’s directive requires affected organizations to apply vendor-supplied mitigations in accordance with Binding Operational Directive (BOD) 26-04, which prioritizes security updates based on risk exposure.
Organizations must also follow CISA’s Forensics Triage Requirements guidance where applicable. Key remediation steps include:
- Apply SimpleHelp’s official patch or mitigation guidance immediately
- For cloud-hosted services, follow BOD 26-04 cloud-specific guidance or discontinue use if mitigations are unavailable
- Review authentication logs for signs of forged OIDC token usage or unauthorized technician session creation
Organizations using SimpleHelp with OIDC authentication enabled should treat this as a high-priority incident, given the combination of unauthenticated exploitation, potential MFA bypass, and the sensitive access level technician sessions typically provide.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.