CVE-2026-8398 is a supply chain attack that compromised DAEMON Tools Lite installation packages with embedded malicious code. This is not a traditional network vulnerability but rather a software integrity issue requiring user download and installation of trojanized software.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: USER_INTERACTION
CVE Published: 2026-05-15
Added to CISA KEV: 2026-05-27 12 DAYS BETWEEN CVE AND KEV
CVE-2026-8398 refers to a supply chain attack rather than a traditional software vulnerability exploitable via remote network vectors [2] [1].
The following details summarize the nature of this incident:
A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendβ¦
A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), ... ... A vulnerability has been identified, and possibly a CVE has been assigned, why is it not in your database? Although a CVE ID may have been assigned byβ¦