One RMM platform. Every MSP client behind it. CVSS 10.0.

CVE-2026-48558 in SimpleHelp's remote monitoring and management platform scores a perfect 10. The TaskWeaver loader is already being deployed through it. If your MSP uses SimpleHelp, this is not their problem. It is yours.
WHY RMM SOFTWARE IS THE WORST PLACE FOR A CVSS 10.0
Remote monitoring and management tools exist specifically to give one operator privileged, trusted access across many downstream client networks simultaneously. That is the entire value proposition. It is also the entire blast radius the moment the platform itself is compromised.
A vulnerability in endpoint software affects one machine. A vulnerability in the RMM tool an MSP uses affects every client network that trusted the MSP's access.
WHAT ATTACKERS ARE DOING WITH IT
CVE-2026-48558 is being exploited to deploy the TaskWeaver loader — a foothold mechanism that establishes persistence before the follow-on payload arrives. This is the supply-chain pattern security teams have warned about for years: compromise the trusted tool, inherit access to everyone who trusts it.
Your organization does not need to run SimpleHelp directly to be exposed. It needs an MSP relationship with someone who does.
WHAT TO DO IMMEDIATELY
ASK YOUR MSP DIRECTLY — do not assume they will proactively disclose. Ask whether they run SimpleHelp, whether it is patched, and whether they have hunted for TaskWeaver indicators in your environment specifically.
AUDIT THIRD-PARTY REMOTE ACCESS TOOLS ON YOUR NETWORK — inventory every RMM agent with a presence in your environment, not just the ones you provisioned yourself.
HUNT FOR TASKWEAVER ARTIFACTS INDEPENDENTLY — do not wait on your MSP's timeline if your contract allows your own security team to inspect endpoints.
TREAT VENDOR TRUST AS A REVOCABLE GRANT, NOT A PERMANENT STATE — a CVSS 10.0 in a tool with privileged cross-tenant access should trigger the same incident response urgency as a breach of your own perimeter, because functionally, it is one.
The MSP model works by extending trust outward. This CVE is a reminder that trust extended is risk inherited.
Do you know every RMM platform with standing access into your network right now?