critical Known exploitedREV. 01

CVE-2026-8398Daemon Tools Lite — trojanized installers signed with the real key

Windows installers for Daemon Tools Lite 12.5.0.2421 through 12.5.0.2434, downloaded from the vendor's own site between April and May 2026, carried three backdoored programs signed with the vendor's genuine code-signing key.

YOUR NEXT MOVE

Remove Daemon Tools Lite from machines that installed it between 8 April and 5 May 2026, treat those hosts as compromised, and rotate the credentials used on them.

Read the risk

THE VITAL STATS
CVSS score
9.3/ 10
CVSS v4.0
EPSS probability
1%
Likelihood of exploitation
Attack complexity
Low
Conditions needed to exploit
Known exploited
Yes — CISA KEV
CVE published
2026-05-15
Added to KEV
2026-05-27
Exploit published
Yes
Confidence
high
Kill chain
initial access
MITRE ATT&CK
—
Severity
critical

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attacker needsThe victim installed Daemon Tools Lite from the vendor site during the four weeks the packages were trojanized.

Behind the card

4 REFERENCES
Field-level provenanceTRACE THE SOURCES +

Which source supports each field, when it was retrieved, and who extracted it.

FieldsSourceRetrievedExtractorConfidence
cvss, exploitation.attack_complexity, exploitation.exploit_available, references, published_atnvd.nist.gov2026-09-24scrty-crds-pipeline/0.1high
exploitation.known_exploited, exploitation.kev_addedcisa.gov2026-09-24scrty-crds-pipeline/0.1high
epssapi.first.org2026-09-24scrty-crds-pipeline/0.1high
title, summary, severity, remediation, mitre_attack, kill_chain, recommended_action, confidence, tags, exploitation.prerequisitesnvd.nist.gov2026-09-24claude-codehigh

Printing history

THE RECORD
  1. r1Initial base card

First printing. This card has not been reprinted since publication.

crds:cve-2026-8398 · CRDS 0.1 · Issued 2026-09-24