Back to overview

CVE-2026-8398

CRITICAL KEV CISA Exploitation: ACTIVE
9.8
CVSS 3.1
Description
A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendor's (AVB Disc Soft) build or distribution infrastructure and trojanized three binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. These files were digitally signed with the legitimate AVB Disc Soft code-signing certificate, allowing the malicious installers to appear trustworthy and bypass signature-based detection.

Metadata

CVE ID
CVE-2026-8398
State
PUBLISHED
Assigner
Kaspersky
Reserved
2026-05-12 13:20 UTC
Published
2026-05-15 07:30 UTC
Last updated
2026-05-28 03:55 UTC
Primary CWE
CWE-506
CWE-506: Embedded Malicious Code
Vendor / Product
AVB Disc Soft / DAEMON Tools Lite
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
ACTIVE
Automatable
yes
Tech. Impact
total
CISA Known Exploited Vulnerability
Vulnerability name
Daemon Tools Lite Embedded Malicious Code Vulnerability
Vendor
Daemon
Product
Daemon Tools Lite
Added to KEV
2026-05-27
Due date
2026-05-30
Ransomware
Not known
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA description
Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability.
Affected products (1)
VendorProductPlatformVersions
AVB Disc Soft DAEMON Tools Lite Windows 12.5.0.2421 < 2.6.0.*
Weakness (CWE)
CWESourceDescription
CWE-506 cna CWE-506: Embedded Malicious Code
CVSS scores (2)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.3 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
References (2)
Back to overview