CISA has added CVE-2026-48558, an authentication bypass vulnerability in SimpleHelp remote support software, to its Known Exploited Vulnerabilities (KEV) Catalog after confirming evidence of active exploitation in the wild. Authentication bypass flaws are a recurring attack vector because they let adversaries sidestep login controls and gain unauthorized access without valid credentials.
Remote support and remote-access tools like SimpleHelp are high-value targets: a successful bypass can hand attackers control over managed endpoints, enabling lateral movement, credential theft, and broader compromise of identity infrastructure. Under BOD 26-04, federal civilian agencies must prioritize rapid remediation of KEV-listed flaws on publicly exposed assets and check whether systems were compromised prior to patching.
What to take away: Organizations running SimpleHelp should patch immediately, restrict external exposure of the management interface, and hunt for signs of pre-patch compromise given the authentication bypass nature of this flaw.