<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — SimpleHelp</title><description>Vulnerabilities and patches in SimpleHelp&apos;s remote-support server — an on-prem RMM/support tool whose compromise typically hands attackers pre-authenticated technician access to every endpoint enrolled behind it. Covered here because remote-support servers are a repeat target for ransomware crews and CISA has added multiple SimpleHelp flaws to its Known Exploited Vulnerabilities catalog. Combined article + CVE feed for the SimpleHelp beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>CVE-2024-57726 — SimpleHelp Missing Authorization Vulnerability</title><link>https://0daynews.com/cve/cve-2024-57726/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-57726/</guid><description>SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>SimpleHelp</category><category>critical</category><category>cve</category></item><item><title>CVE-2024-57727 — SimpleHelp Path Traversal Vulnerability</title><link>https://0daynews.com/cve/cve-2024-57727/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-57727/</guid><description>SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files may include server configuration files and hashed user passwords.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>SimpleHelp</category><category>high</category><category>cve</category></item><item><title>CVE-2024-57728 — SimpleHelp Path Traversal Vulnerability</title><link>https://0daynews.com/cve/cve-2024-57728/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-57728/</guid><description>SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>SimpleHelp</category><category>high</category><category>cve</category></item><item><title>CVE-2026-48558 — SimpleHelp OIDC Authentication Bypass</title><link>https://0daynews.com/cve/cve-2026-48558/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-48558/</guid><description>SimpleHelp 5.5.15 and prior accepts OIDC identity tokens without verifying their signature — a forged token yields a full technician session. CVSS 10.0, KEV, patch is 5.5.16.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>SimpleHelp</category><category>critical</category><category>cve</category></item><item><title>SimpleHelp OIDC Auth Bypass Past CISA Deadline: Patch Now</title><link>https://0daynews.com/articles/2026-07-09-simplehelp-cve-2026-48558-oidc-bypass-past-kev-deadline/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-09-simplehelp-cve-2026-48558-oidc-bypass-past-kev-deadline/</guid><description>SimpleHelp Server 5.5.15 and earlier accept forged OIDC tokens as valid technician sessions. CVSS 10.0, KEV, patch is 5.5.16 — CISA deadline was July 2.</description><pubDate>Thu, 09 Jul 2026 04:00:00 GMT</pubDate><category>SimpleHelp</category><category>article</category></item></channel></rss>