Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-8398
AVB Disc Soft DAEMON Tools Lite — Daemon Daemon Tools Lite
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H H H 9.3 .0096 60.3 YES
AFFECTED
Product Versions Fixed
DAEMON Tools Lite 12.5.0.2421 – —
TIMELINE
May 12 Reserved by Kaspersky
May 15 Published (CNA: Kaspersky)
May 27 Added to CISA KEV, remediation due 2026-05-30
May 31 DUE DATE PASSED — CVE-2026-8398 (Daemon Tools Lite). CISA remediation deadline was May 30, 2026; still in catalog.
Description
A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendor's (AVB Disc Soft) build or distribution infrastructure and trojanized three binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. These files were digitally signed with the legitimate AVB Disc Soft code-signing certificate, allowing the malicious installers to appear trustworthy and bypass signature-based detection.
Lifecycle
Complete event history — 4 events, chronological
| Date | Event | Detail |
| May 12, 2026 | Reserved | Reserved by Kaspersky |
| May 15, 2026 | Published | Published (CNA: Kaspersky) |
| May 27, 2026 | KEV ADDED | Added to CISA KEV, remediation due 2026-05-30 |
| May 31, 2026 | DUE DATE PASSED | DUE DATE PASSED — CVE-2026-8398 (Daemon Tools Lite). CISA remediation deadline was May 30, 2026; still in catalog. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| AVB Disc Soft | DAEMON Tools Lite | — | 12.5.0.2421 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-8398 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.