CVE-2026-8398

CRITICAL(9.8)KEV

Daemon Tools Lite Embedded Malicious Code Vulnerability

Description

CVE-2026-8398 is a critical supply chain vulnerability in DAEMON Tools Lite caused by embedded malicious code. Between approximately April 8 and May 5, 2026, attackers compromised the build or distribution infrastructure of vendor AVB Disc Soft and trojanized three binaries — DTHelper.exe, DiscSoftBusServiceLite.exe and DTShellHlp.exe — in the official installers (Windows versions 12.5.0.2421 through 12.5.0.2434) served from the legitimate daemon-tools.cc website. Because the malicious files were signed with the genuine AVB Disc Soft code-signing certificate, they appeared trustworthy and bypassed signature-based detection, letting attacker-controlled code run on victim systems. With a CVSS score of 9.8 and a CISA KEV listing, CVE-2026-8398 is being exploited in the wild and affected DAEMON Tools Lite installations should be remediated immediately.

KEV Information

Vendor
Daemon
Product
Daemon Tools Lite
Date Added
May 27, 2026
Due Date
May 30, 2026
Required Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
disc-softdaemon tools12.5.1

References

Weakness Type

CWE-506: Embedded Malicious Code

Embedded malicious code is hostile logic intentionally introduced into otherwise legitimate software. In CVE-2026-8398 the attacker did not exploit a coding flaw but instead trojanized official DAEMON Tools Lite binaries and distributed them through the vendor's own signed installers, so the malware executed under the guise of trusted, properly signed software.

Learn more: CWE-506 — Embedded Malicious Code

Impact Analysis

CVE-2026-8398 carries a CVSS 3.1 score of 9.8 (CRITICAL). The CVSS vector describes an attack that is remotely exploitable through the software distribution channel (Attack Vector: Network), low-complexity (Attack Complexity: Low), requires no privileges (Privileges Required: None) and no user interaction beyond the routine act of downloading and installing the software (User Interaction: None), with High impact to confidentiality, integrity and availability. Because the trojanized binaries were signed with the legitimate AVB Disc Soft certificate, they bypassed signature-based defenses and ran as trusted software — giving the embedded code broad access to the host to steal data, establish persistence and tamper with the system. The EPSS score of 14.4% sits in the 94.5th percentile, and the CISA KEV listing confirms active exploitation, so any system that installed an affected version should be treated as compromised.

Exploit Maturity

CVE-2026-8398 is a realized supply chain compromise that was actively distributed to users, not a theoretical weakness. The trojanized installers were served from the official daemon-tools.cc site for roughly a month, and CISA has added the CVE to its Known Exploited Vulnerabilities catalog, confirming exploitation in the wild. A detailed third-party technical analysis with indicators of compromise is available from Kaspersky's Securelist (tagged as an exploit reference), and the vendor has acknowledged the incident at blog.daemon-tools.cc. With an EPSS score of 14.4% (94.5th percentile) and confirmed distribution of signed malware, defenders should hunt for the affected binaries and indicators immediately rather than wait.

Remediation

  1. Apply mitigations per vendor instructions as mandated by the CISA KEV deadline of 2026-05-30, and follow the vendor advisory at blog.daemon-tools.cc.
  2. Identify any DAEMON Tools Lite installations in the affected range (Windows 12.5.0.2421 through 12.5.0.2434 installed between April 8 and May 5, 2026), uninstall them, and reinstall only a clean, vendor-confirmed build obtained after the incident was remediated.
  3. Treat affected hosts as compromised: scan for and remove the trojanized DTHelper.exe, DiscSoftBusServiceLite.exe and DTShellHlp.exe, then rotate credentials and secrets that were present on those machines.
  4. Hunt for indicators of compromise from the Securelist analysis — backdoor persistence, outbound connections to attacker infrastructure and signs of data theft — across endpoint and network telemetry; do not rely on code-signature validation alone, since the malicious files carried a legitimate signature.
  5. As long-term hardening against embedded malicious code in signed software, verify file hashes against vendor-published values, monitor for unexpected behavior from signed binaries, and apply application allow-listing and EDR behavioral detection that does not depend solely on signature trust.

Technical Details

CVE-2026-8398 is embedded malicious code (CWE-506) delivered through a vendor supply chain compromise. Attackers gained unauthorized access to AVB Disc Soft's build or distribution infrastructure and replaced three DAEMON Tools Lite binaries — DTHelper.exe, DiscSoftBusServiceLite.exe and DTShellHlp.exe — with trojanized versions in the official installers distributed from daemon-tools.cc, affecting Windows builds 12.5.0.2421 through 12.5.0.2434 between approximately April 8 and May 5, 2026. Critically, the malicious binaries were digitally signed with the legitimate AVB Disc Soft code-signing certificate, so they passed signature-based trust checks and ran without raising suspicion. The CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) reflects a network-distributed, unauthenticated compromise with high impact across confidentiality, integrity and availability.

Frequently Asked Questions

Is CVE-2026-8398 being actively exploited?

Yes. CVE-2026-8398 is a realized supply chain attack: trojanized DAEMON Tools Lite installers were distributed from the official website, and CISA has listed the CVE on its Known Exploited Vulnerabilities catalog. Its EPSS score of 14.4% (94.5th percentile) further indicates high exploitation likelihood.

What products are affected by CVE-2026-8398?

The affected product is DAEMON Tools Lite for Windows, versions 12.5.0.2421 through 12.5.0.2434, distributed from daemon-tools.cc between approximately April 8 and May 5, 2026. The trojanized binaries are DTHelper.exe, DiscSoftBusServiceLite.exe and DTShellHlp.exe.

How do I fix CVE-2026-8398?

Uninstall any affected DAEMON Tools Lite version, remove the trojanized binaries, and reinstall a clean vendor-confirmed build released after the incident. Because the malware was signed and ran with system access, treat affected hosts as compromised and rotate credentials.

How severe is CVE-2026-8398?

CVE-2026-8398 is rated CRITICAL with a CVSS 3.1 score of 9.8. It distributed signed, attacker-controlled code with high confidentiality, integrity and availability impact and is confirmed as actively exploited by CISA — making immediate remediation essential.

CVSS Score

9.8
CRITICAL(9.8)

EPSS Score

EPSS Score1.46%
EPSS Percentile71.4%

Dates

PublishedMay 15, 2026
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.