<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — SimpleHelp </title><description>Actively exploited vulnerabilities affecting SimpleHelp  products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/simplehelp.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-48558 — SimpleHelp Authentication Bypass Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-48558</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-48558</guid><description>SimpleHelp&apos;s OIDC authentication flow fails to verify the cryptographic signatures of identity tokens at login. This means an unauthenticated attacker can craft a forged token with any identity claims they choose and receive a fully authenticated technician session in return. In some configurations, this also bypasses multi-factor authentication entirely. Since SimpleHelp is remote support software, a successful exploit gives attackers technician-level access to managed endpoints — a serious risk for any organization using OIDC-based login.</description><pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate><category>SimpleHelp </category><category>SimpleHelp</category></item><item><title>CVE-2024-57726 — SimpleHelp Missing Authorization Vulnerability</title><link>https://wildfortech.com/security#CVE-2024-57726</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2024-57726</guid><description>This flaw in SimpleHelp allows low-privileged technicians to generate API keys that carry far more permissions than their account should allow. By exploiting these over-privileged keys, an attacker can escalate all the way to full server administrator access. The vulnerability has already been linked to ransomware activity, meaning real-world attackers are actively leveraging it — making exposure through any internet-facing SimpleHelp deployment particularly dangerous.</description><pubDate>Fri, 24 Apr 2026 00:00:00 GMT</pubDate><category>SimpleHelp </category><category>SimpleHelp</category></item><item><title>CVE-2024-57728 — SimpleHelp Path Traversal Vulnerability</title><link>https://wildfortech.com/security#CVE-2024-57728</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2024-57728</guid><description>SimpleHelp, a remote support tool, contains a path traversal flaw where admin-level users can upload a specially crafted zip file that places files anywhere on the server&apos;s filesystem — a classic &apos;zip slip&apos; attack. This allows attackers to achieve arbitrary code execution running as the SimpleHelp server process. The vulnerability is already linked to active ransomware campaigns, making unpatched installations a high-priority target for significant business disruption.</description><pubDate>Fri, 24 Apr 2026 00:00:00 GMT</pubDate><category>SimpleHelp </category><category>SimpleHelp</category></item></channel></rss>