peter bassill · operator
$ cve CVE-2026-8398 JSON

CVE-2026-8398 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 1% (pctl 60)

Patch first

On CISA KEV — known exploited in the wild, due 2026-05-30.

Description

A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendor's (AVB Disc Soft) build or distribution infrastructure and trojanized three binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. These files were digitally signed with the legitimate AVB Disc Soft code-signing certificate, allowing the malicious installers to appear trustworthy and bypass signature-based detection.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.96% — more likely to be exploited than 60% of all CVEs
WeaknessCWE-506
On CISA KEVyes — remediate by 2026-05-30
Public exploitnone known
Published2026-05-15
Last modified2026-06-17

CISA KEV

NameDaemon Tools Lite Embedded Malicious Code Vulnerability
Added2026-05-27
Due2026-05-30
Vendor / productDaemon / Daemon Tools Lite
Ransomware usenone reported

Affected (2)

VendorProduct
disc-softdaemon tools
microsoftwindows

References

→ the Explorer  ·  watch your stack  ·  NVD