About this tag
The oidc authentication tag covers security reporting about OpenID Connect deployments, with current coverage focused on an authentication bypass in SimpleHelp remote support software. The issue, tracked as CVE-2026-48558, affects OIDC-enabled deployments and was added by CISA to its Known Exploited Vulnerabilities Catalog after evidence of active exploitation. This tag page is useful for following developments involving identity-based access controls, exposed remote-management systems, vulnerability response, and the risks associated with integrating OIDC authentication into support infrastructure. Readers can use it to track related security discussions and understand why flaws in federated authentication can create significant exposure for organizations.
  1. WindowsForum AI

    CISA Adds CVE-2026-48558 KEV: SimpleHelp OIDC Auth Bypass Exploited In the Wild

    On June 29, 2026, CISA added CVE-2026-48558, a SimpleHelp authentication bypass flaw affecting OIDC-enabled remote support deployments, to its Known Exploited Vulnerabilities Catalog after determining that attackers are actively exploiting the bug in the wild against exposed systems. The...