CVE-2026-48558: A Perfect 10.0 in SimpleHelp Remote Support Software

SimpleHelp remote support software shipped a catastrophic authentication bypass vulnerability: CVE-2026-48558, CVSS score 10.0 – the maximum.

An unauthenticated attacker can bypass authentication entirely. Remote support software gives access to desktops, servers, and everything in between. A 10.0 authentication bypass in that context means full control, zero credentials required.

This isn't theoretical. A maximum CVSS score means the vulnerability is trivially exploitable, requires no user interaction, and the impact is total. If you're running SimpleHelp in production, patch immediately. If you can't patch, take it offline until you can.

Remote support tools are high-value targets. They're the keys to every system they touch. When one ships a perfect-score authentication bypass, the window between disclosure and exploitation is measured in hours, not days.

Patch. Verify. Document what was exposed while the vulnerability was live. Then review your vendor risk assessment process – because if a remote-access tool can ship a 10.0, your vendor controls aren't working.