Bugs in remote support tools that grant remote access to customer devices are bad... I've been told. Could be wrong too!

Tenable Discovers Critical Vulnerabilities in SimpleHelp Tool: CVE-2025-36727 and CVE-2025-36728
Tenable Research found two vulnerabilities in the SimpleHelp remote support tool that when chained could lead to remote code execution.
Tenable® (www.tenable.com)