CVE-2026-8398
Daemon Tools Lite Embedded Malicious Code Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 30 May 2026). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendor's (AVB Disc Soft) build or distribution infrastructure and trojanized three binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. These files were digitally signed with the legitimate AVB Disc Soft code-signing certificate, allowing the malicious installers to appear trustworthy and bypass signature-based detection.
- CVSS 4.0
- 9.3 CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 1.46% probability · 72th percentile
- CISA KEV
- Listed 27 May 2026 · due 30 May 2026
- Weakness
- CWE-506
- Affected
- disc-soft/daemon tools
- Source
- vulnerability@kaspersky.com
CISA notes
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://blog.daemon-tools.cc/post/security-incident ; https://nvd.nist.gov/vuln/detail/CVE-2026-8398
References
- https://blog.daemon-tools.cc/post/security-incidentVendor Advisory
- https://securelist.com/tr/daemon-tools-backdoor/119654/Exploit, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-8398US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.