CVE-2026-8398 Details
Description
A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendor's (AVB Disc Soft) build or distribution infrastructure and trojanized three binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. These files were digitally signed with the legitimate AVB Disc Soft code-signing certificate, allowing the malicious installers to appear trustworthy and bypass signature-based detection.
A supply chain attack has compromised the official installation packages of DAEMON Tools Lite for Windows, specifically versions 12.5.0.2421 to 12.5.0.2434. These packages were distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. During this period, attackers gained unauthorized access to the vendor's build or distribution infrastructure and trojanized three binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. These malicious binaries were digitally signed with the legitimate AVB Disc Soft code-signing certificate, allowing them to bypass signature-based detection and appear trustworthy.
Users are advised to uninstall DAEMON Tools Lite version 12.5.1 (free) and run a full system scan with trusted security software. The latest version of DAEMON Tools Lite (12.6) can be downloaded from the official website. For those using other DAEMON Tools products, including paid versions of DAEMON Tools Lite, DAEMON Tools Ultra, and DAEMON Tools Pro, no action is needed as these products are not affected by the incident.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-8398 | CISA-ADP | US Government Resource |
| https://blog.daemon-tools.cc/post/security-incident | [email protected] | Vendor Advisory |
| https://securelist.com/tr/daemon-tools-backdoor/119654/ | [email protected] | ExploitThird Party Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Daemon Tools Lite Embedded Malicious Code Vulnerability | May 27, 2026 | May 30, 2026 | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-506 | Embedded Malicious Code | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| disc-soft daemon tools | 12.5.1 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 28, 2026 | Initial Analysis | [email protected] |
| May 27, 2026 | CVE Modified | CISA-ADP |
| May 27, 2026 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| May 15, 2026 | New CVE Received | [email protected] |