CISA Sets a July 2 Deadline as SimpleHelp Auth-Bypass Flaw CVE-2026-48558, Rated CVSS 10, Is Exploited to Deploy Djinn Stealer
A perfect-score authentication bypass in SimpleHelp's OIDC login is being exploited in the wild to deploy TaskWeaver and Djinn Stealer, prompting CISA to give federal agencies until July 2 to patch.