Skip to content
Actively exploitedCVSS 9.8 · CRITICAL

CVE-2026-8398

Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability.

View on NVD

Analysis

A supply chain attack compromised official DAEMON Tools Lite installers (versions 12.5.0.2421 to 12.5.0.2434) between April and May 2026. Malicious binaries were signed with the legitimate vendor certificate to bypass detection. If you have used this utility recently, check for trojanized files like DTHelper.exe or DiscSoftBusServiceLite.exe.

Severity

Score: 9.8(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-506

CISA KEV

Added to KEV: 2026-05-27
Federal patch deadline: 2026-05-30
Known ransomware use: Unknown
Required action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

EPSS

Probability of exploitation (next 30 days): 0.0004 (0.0%)
Percentile: 12.3%
EPSS: 2026-05-27

Technical description

A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendor's (AVB Disc Soft) build or distribution infrastructure and trojanized three binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. These files were digitally signed with the legitimate AVB Disc Soft code-signing certificate, allowing the malicious installers to appear trustworthy and bypass signature-based detection.

Published: 5/15/2026, 9:16:17 AM
Last modified: 5/27/2026, 7:16:24 PM

References

HomeEventsBlogResourcesTeam