Initiatives for As the national authority for Cybersecurity the CCB has developed several initiatives for specific publics which are presented here. - Last update: 18/06/2026 - Affected software: → SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions.- Type: authentication bypass vulnerability - CVE/CVSS → CVE-2026-48558 CVSS 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) SimpleHelp - https://simple-help.com/security/simplehelp-security-update-2026-05 SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OpenID Connect (OIDC) authentication flow. The vulnerability can be exploited in specific conditions depending on the server's settings and network context. SimpleHelp is a commercial remote support and remote access platform used by IT administrators, managed service providers (MSPs), help desks, and organisations to remotely connect to and manage. Successful exploitation of the vulnerability could allow unauthenticated attackers to create a new “Technician” account and use it to remote into managed endpoints, execute scripts, install programs; or view, change, or delete data. A video demonstrating the exploitation of the vulnerability was published, increasing the risk of exploitation. CVE-2026-48558 (CVSS 10) is a critical vulnerability in SimpleHelp that allows for OIDC authentication bypass. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication, by accepting forged tokens without verifying their cryptographic signatures. Patch SimpleHelp addressed the vulnerability in a security advisory with updated versions. The Centre for Cybersecurity Belgium strongly recommends installing updates for vulnerable devices with the highest priority after thorough testing. Monitor/Detect The CCB recommends organizations upscale monitoring and detection capabilities to identify any related suspicious activity and ensure a swift response in case of an intrusion. In case