SB2026050672 - Backdoor in DAEMON Tools software



SB2026050672 - Backdoor in DAEMON Tools software

Published: May 6, 2026

Security Bulletin ID SB2026050672
CSH Severity
Critical
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Critical 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Embedded malicious code (backdoor) (CVE-ID: N/A)

The vulnerability allows a remote attacker to gain unauthorized access to the system.

The vulnerability exists due to presence of embedded malicious functionality (aka backdoor) in the application's installer, downloaded from the official website. A remote attacker can compromise the affected system after installing the infected version of DAEMON Tools software.

Note, the vendor's website was distributing infected version since April 8, 2026. 


Remediation

Install update from vendor's website.