Simple Help is a remote-support and access application with a narrow product footprint but a meaningful presence among organizations relying on vendor-managed technical assistance. The vendor's vulnerability profile centers on its core remote-access product and reflects the input-handling and authentication challenges inherent to software exposing management interfaces over the network. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Simple Help over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-57727HIGH SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary fil | Jan 15, 2025 | 7.5 | 98 | YES | YES |
CVE-2026-48558CRITICAL SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is config | Jun 12, 2026 | 10.0 | 84 | YES | NO |
CVE-2024-57726CRITICAL SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be | Jan 15, 2025 | 9.9 | 76 | YES | NO |
CVE-2024-57728HIGH SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This | Jan 15, 2025 | 7.2 | 68 | YES | NO |
CVE-2025-36728HIGH Cross-Site Request Forgery (CSRF) vulnerability in Simplehelp.This issue affects Simplehelp: before 5.5.11. | Jul 25, 2025 | 8.8 | 30 | NO | NO |
CVE-2025-36727HIGH Inclusion of Functionality from Untrusted Control Sphere vulnerability in Simplehelp.This issue affects Simplehelp: before 5.5.12. | Jul 25, 2025 | 8.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Simple Help.
Media articles that mention a CVE ID that affects a product developed by Simple Help — matched by CVE ID, not by vendor name.