SB2026050672 - Backdoor in DAEMON Tools software
Published: May 6, 2026 Updated: May 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Embedded malicious code (backdoor) (CVE-ID: CVE-2026-8398)
CWE-ID: CWE-506 - Embedded Malicious Code
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Red
The vulnerability allows a remote attacker to gain unauthorized access to the system.
The vulnerability exists due to presence of embedded malicious functionality (aka backdoor) in the application's installer, downloaded from the official website. A remote attacker can compromise the affected system after installing the infected version of DAEMON Tools software.
Note, the vendor's website was distributing infected version since April 8, 2026.
Remediation
Install update from vendor's website.