← Vulnerability feed

Vulnerability record · CVE-2026-8398 · published 15 May 2026

CVE-2026-8398: DAEMON Tools Lite installers trojanized via supply chain compromise

Disc Soft · Daemon Tools

Attackers breached AVB Disc Soft's build or distribution infrastructure and trojanized three signed binaries (DTHelper.exe, DiscSoftBusServiceLite.exe, DTShellHlp.exe) shipped in DAEMON Tools Lite Windows installers 12.5.0.2421 through 12.5.0.2434 from daemon-tools.cc between roughly April 8 and May 5, 2026. Because the files carry the legitimate vendor code-signing certificate, signature-based trust and detection are bypassed. This is a confirmed supply chain compromise of a widely distributed consumer application, not a coding bug in the product itself.

9.3 CVSS 4.0 Critical CISA KEV since 27 May 2026 EPSS 0.96% · top 39.9% CWE-506 · CWE-506
9.3CVSS 4.0 base score
0.96%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendor's (AVB Disc Soft) build or distribution infrastructure and trojanized three binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. These files were digitally signed with the legitimate AVB Disc Soft code-signing certificate, allowing the malicious installers to appear trustworthy and bypass signature-based detection.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityA confirmed, signed supply chain compromise of a widely distributed installer that is listed in CISA KEV with a CVSS 4.0 score of 9.3 and no authentication barrier.

What it is

Attackers breached AVB Disc Soft's build or distribution infrastructure and trojanized three signed binaries (DTHelper.exe, DiscSoftBusServiceLite.exe, DTShellHlp.exe) shipped in DAEMON Tools Lite Windows installers 12.5.0.2421 through 12.5.0.2434 from daemon-tools.cc between roughly April 8 and May 5, 2026. Because the files carry the legitimate vendor code-signing certificate, signature-based trust and detection are bypassed. This is a confirmed supply chain compromise of a widely distributed consumer application, not a coding bug in the product itself.

Impact

An attacker gains code execution on any host that installed an affected package, with the malicious binaries running under the vendor's legitimate signature. The record does not state the specific payload or post-exploitation behavior beyond the backdoor reference.

Attack surface

Reached by downloading and installing the affected DAEMON Tools Lite package from the legitimate vendor site; no authentication or special user interaction beyond running the installer is required, consistent with the CVSS 4.0 vector AV:N/PR:N/UI:N. The compromise is in the distribution channel, not in a remotely reachable service.

Exploitation

Listed in CISA KEV (added 2026-05-27, due 2026-05-30), indicating known exploitation in the wild; EPSS 30-day probability is 0.01456 (72nd percentile), and a third-party reference is tagged Exploit. No ransomware campaign use is documented.

What to do

  • Remove or reinstall DAEMON Tools Lite using a package confirmed clean by the vendor; do not trust existing installs of versions 12.5.0.2421 through 12.5.0.2434.
  • Follow the vendor security incident advisory and CISA KEV required action, including BOD 22-01 guidance for cloud services or discontinuing the product if mitigations are unavailable.
  • Hunt for and block the three trojanized binaries (DTHelper.exe, DiscSoftBusServiceLite.exe, DTShellHlp.exe) by hash where available, and treat their presence as compromise.
  • Do not rely on code-signing validation alone for this vendor's packages; verify hashes against vendor-published clean values before deployment.
  • Rotate credentials and review systems that ran affected installers for signs of backdoor persistence or lateral movement.

Detection

  • Search endpoint telemetry for execution of DTHelper.exe, DiscSoftBusServiceLite.exe, or DTShellHlp.exe outside expected install paths or after the incident window.
  • Alert on DAEMON Tools Lite installer files matching versions 12.5.0.2421 to 12.5.0.2434 or downloaded from daemon-tools.cc between April 8 and May 5, 2026.
  • Monitor for outbound network connections or child processes spawned by the three named binaries, which are not expected to initiate such activity.
  • Correlate file creation of the signed binaries with subsequent persistence or credential-access behavior on the same host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-8398 to the Known Exploited Vulnerabilities catalog on 27 May 2026 as "Daemon Tools Lite Embedded Malicious Code Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 30 May 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-8398 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-21832Disc-soft daemon tools integer overflow vulnerabilityA memory corruption vulnerability exists in the ISO Parsing functionality of Disc Soft Ltd Deamon Tools Pro 8.3.0.0767. A specially crafted malformed…EPSS 1.2%9.3CVE-2026-48027Nx Console VS Code extension shipped with embedded malicious codeA malicious version of the Nx Console extension, 18.95.0, was published to the Visual Studio Marketplace and OpenVSX and remained downloadable for ro…KEVEPSS 1.3%analysed9.6CVE-2026-45321TanStack npm packages published with credential-stealing malware via CI/CD chainEighty-four malicious versions across 42 @tanstack/* npm packages were published on 2026-05-11 using the legitimate GitHub Actions OIDC trusted-publi…KEVEPSS 1.1%analysed9.4CVE-2026-33634Trivy and trivy-action supply chain compromise via malicious release and tagsA threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in aquasecurity/trivy-acti…KEVEPSS 1.7%analysed7.5CVE-2025-54313eslint-config-prettier npm package ships malicious install scriptVersions 8.10.1, 9.1.1, 10.1.6 and 10.1.7 of eslint-config-prettier contain embedded malicious code: installing the package runs an install.js that l…KEVEPSS 4.5%analysed9.3CVE-2025-59374ASUS Live Update client supply chain compromise with embedded malicious codeCertain builds of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modi…KEVEPSS 1.2%analysed8.6CVE-2025-30154reviewdog/action-setup GitHub Action leaks secrets to workflow logsreviewdog/action-setup@v1 was compromised on March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets into G…KEVEPSS 2.4%analysed8.6CVE-2025-30066tj-actions/changed-files GitHub Action leaks secrets via modified tagsThe tj-actions/changed-files GitHub Action was compromised: tags v1 through v45.0.7 were modified on 2025-03-14 and 2025-03-15 to point at commit 0e5…KEVEPSS 72%analysed

Source: NIST National Vulnerability Database (record CVE-2026-8398), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.