Supply Chain Vulnerability in DAEMON Tools Lite by AVB Disc Soft
CVE-2026-8398
Key Information:
- Vendor
Avb Disc Soft
- Status
- Vendor
- CVE Published:
- 15 May 2026
Badges
What is CVE-2026-8398?
CVE-2026-8398 is a significant supply chain vulnerability affecting DAEMON Tools Lite, a widely used software application for disk imaging and virtual drive management developed by AVB Disc Soft. This vulnerability arises from an unauthorized compromise of the official installation packages distributed from the legitimate DAEMON Tools website between early April and early May 2026. Attackers exploited weaknesses in the vendor’s build and distribution infrastructure, resulting in the trojanization of key binaries—DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe—within specific software versions. These compromised files were signed with a valid AVB Disc Soft code-signing certificate, which allowed them to bypass standard security measures that rely on such signatures for authenticity, making the malicious installers appear legitimate. Consequently, organizations using DAEMON Tools Lite are at a heightened risk of malware infiltration, which can jeopardize the integrity of their systems and sensitive data.
Potential impact of CVE-2026-8398
-
Malware Installation: The main impact of this vulnerability is the potential for malware to be installed on affected systems, as the trojanized files can facilitate unauthorized access and control, leading to a range of malicious activities.
-
Data Compromise: With attackers potentially able to execute arbitrary code, there is a significant risk of data breaches, where sensitive organizational information can be accessed, exfiltrated, or manipulated.
-
Reputation Damage: Organizations affected by the exploitation of this vulnerability may face reputational harm as a result of data breaches or malware incidents, which could undermine customer trust and impact business operations and partnerships.
CISA has reported CVE-2026-8398
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-8398 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace
The CISA's recommendation is: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Affected Version(s)
DAEMON Tools Lite Windows 12.5.0.2421 < 2.6.0.*
References
CVSS V4
Timeline
- 👾
Exploit known to exist
- 🦅
CISA Reported
Vulnerability published
Vulnerability Reserved
