Web_Logo
Remote Support
Security Alert: SimpleHelp RMM Under Active Attack – Patch Now
Home » Security Alerts  »  Security Alert: SimpleHelp RMM Under Active Attack – Patch Now

Security Alert: SimpleHelp RMM Under Active Attack – Patch Now

A critical vulnerability in SimpleHelp remote support software is being actively exploited by attackers to steal business credentials and install malware. This is a serious threat affecting any organisation whose IT support team runs a SimpleHelp server accessible from the internet.

  • What it is: CVE-2026-48558 is an authentication bypass flaw in SimpleHelp, a remote monitoring and management (RMM) tool widely used by IT teams and managed service providers (MSPs).
  • Who is affected: Any organisation whose IT provider or internal IT team runs a SimpleHelp server that is accessible from the internet.
  • What attackers are doing: After bypassing authentication, attackers hijack the SimpleHelp server and use it to remotely deploy Djinn Stealer – malware that harvests passwords, cloud service credentials (AWS, Azure, Google Cloud), SSH keys, browser data, and cryptocurrency wallets from managed computers across the entire network.
  • How serious is this: CISA (the US government's cybersecurity agency) has added CVE-2026-48558 to its Known Exploited Vulnerabilities catalogue. US federal agencies have been directed to patch or take action by 7 July 2026.
  • Why this matters for your business: If an attacker gains access to an MSP's SimpleHelp server, they can push malware to every business that MSP manages – not just the MSP itself. The stolen credentials can then provide ongoing access even after the original breach is cleaned up.

What to do: If your IT support provider uses SimpleHelp, ask them to confirm they have applied the latest security patch and checked for signs of compromise. If you manage your own SimpleHelp server, update immediately and review your server logs for suspicious activity.

Sources: Help Net Security | CISA Known Exploited Vulnerabilities Catalogue