P.01CVE-2026-48558: SimpleHelp's Auth Bypass Is an MSP Supply Chain Problem
A forged OIDC token in SimpleHelp RMM lets an unauthenticated attacker create an admin account and reach every endpoint the instance manages. CISA added it to the KEV catalog on June 29. Here's what it means if your agency or your vendors use SimpleHelp.










