{"id":22572,"date":"2026-07-02T11:11:44","date_gmt":"2026-07-02T11:11:44","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/07\/23\/simplehelp-mfa-bypass-exploited-with-critical-10-0-cvss\/"},"modified":"2026-07-23T15:20:52","modified_gmt":"2026-07-23T15:20:52","slug":"simplehelp-mfa-bypass-exploited-with-critical-10-0-cvss","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/07\/02\/simplehelp-mfa-bypass-exploited-with-critical-10-0-cvss\/","title":{"rendered":"SimpleHelp MFA Bypass Exploited with Critical 10.0 CVSS Score"},"content":{"rendered":"<p style=\"color:#69d8ed;font-size:0.9em;margin:0 0 16px;padding:0;\">7 min read<\/p>\n<p><strong>On June 29, the U.S. agency CISA set a deadline for July 2. Three days for anyone running a SimpleHelp server exposed to the internet. The reason: a vulnerability with a CVSS score of 10.0-the maximum. CVE-2026-48558 completely bypasses authentication, multi-factor included, without attackers needing a single password.<\/strong><\/p>\n<div style=\"background:#003340;color:#fff;padding:32px 36px;margin:32px 0;border-radius:8px;\">\n<p style=\"margin:0 0 18px 0;font-size:0.95em;font-weight:800;text-transform:uppercase;letter-spacing:0.2em;color:#69d8ed;border-bottom:2px solid rgba(105,216,237,0.25);padding-bottom:12px;\">Key Takeaways<\/p>\n<ul style=\"margin:0;padding-left:22px;color:rgba(255,255,255,0.92);line-height:1.6;\">\n<li style=\"margin-bottom:10px;\"><strong style=\"color:#69d8ed;\">Authentication bypass with CVSS 10.0:<\/strong> When OIDC is enabled, SimpleHelp fails to validate the signature of identity tokens. A forged token is all it takes to gain a fully authenticated technician session.<\/li>\n<li style=\"margin-bottom:10px;\"><strong style=\"color:#69d8ed;\">MFA neutralized:<\/strong> During first login, technicians register their own second factor. Attackers simply register their own instead.<\/li>\n<li style=\"margin-bottom:10px;\"><strong style=\"color:#69d8ed;\">Actively exploited:<\/strong> Threat actors are using this flaw to distribute two new malware strains, TaskWeaver and Djinn Stealer. CISA\u2019s deadline for federal agencies was July 2.<\/li>\n<li><strong style=\"color:#69d8ed;\">MSPs in the crosshairs:<\/strong> RMM servers sit at the heart of hundreds of client networks for IT service providers. A compromised server is a master key.<\/li>\n<\/ul>\n<\/div>\n<p style=\"font-size:0.88em;color:#b8c5ce;margin:20px 0 32px 0;border-top:1px solid rgba(230,227,218,0.12);border-bottom:1px solid rgba(230,227,218,0.12);padding:10px 0;\"><span style=\"color:#69d8ed;font-weight:700;text-transform:uppercase;font-size:0.72em;letter-spacing:0.14em;margin-right:14px;\">Related:<\/span><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/07\/adaptive-mfa-nis2-pressure-as-a-zero-trust\/\" style=\"color:#333;text-decoration:underline;\">Adaptive MFA as a Zero Trust lever<\/a>&nbsp;&nbsp;<span style=\"color:#ccc;\">\/<\/span>&nbsp;&nbsp;<a href=\"https:\/\/www.securitytoday.de\/en\/2026\/06\/25\/from-when-the-reporting-deadline-clock-really-starts-ticking\/\" style=\"color:#333;text-decoration:underline;\">When the incident reporting clock starts ticking<\/a><\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">What CVE-2026-48558 Actually Breaks<\/h2>\n<p>This vulnerability lies in a spot that comes up in every basic security course. When OIDC authentication is enabled, SimpleHelp accepts identity tokens without verifying their cryptographic signature. In vulnerability taxonomy, this is CWE-347: &#8220;Improper Verification of Cryptographic Signature.&#8221; In plain terms, the server believes any ID you show it without checking the watermark.<\/p>\n<p>An unauthenticated attacker from anywhere on the internet can craft a token claiming to belong to an authorized Technician group. SimpleHelp lets them through and, if needed, even creates a new technician account. The prerequisite is a common real-world configuration: OIDC enabled, a TechnicianGroup linked to the provider, and the &#8220;Allow group authenticated logins&#8221; option turned on.<\/p>\n<p>What about the second line of defense-MFA? It doesn\u2019t help here. Even if the server enforces MFA for technicians, a technician can register their own second factor on first login. The attacker exploits this exact window and enrolls their own authenticator app. The lock is new, but they\u2019ve cut their own key.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Why RMM Servers Are Such an Attractive Target<\/h2>\n<p>SimpleHelp is a remote monitoring and management (RMM) tool. IT service providers and in-house admin teams use it to control their clients&#8217; or branch locations&#8217; computers remotely. Whoever gains control of this server isn\u2019t just inside a single network-they\u2019re at the junction box for many.<\/p>\n<p>That\u2019s precisely what makes this vulnerability so troubling for managed service providers (MSPs) in the DACH region (Germany, Austria, Switzerland). A single compromised RMM server can potentially open the door to cloud consoles, DevOps pipelines, and the credentials behind them. The attacker doesn\u2019t need to breach each customer individually-they take over the provider and inherit its entire reach.<\/p>\n<p>Just how large this exposed attack surface is was examined by Horizon3.ai. Of roughly 14,000 SimpleHelp servers accessible on the internet, about 7.2% were configured with the vulnerable OIDC variant as of June 2026, according to their data. While that may sound like a small percentage, for a tool designed to sit deep within third-party networks, even one such server is one too many.<\/p>\n<div style=\"background:#003340;color:#fff;padding:28px 32px;margin:32px 0;border-radius:8px;\">\n<p style=\"margin:0 0 8px 0;font-size:2.2em;font-weight:800;color:#69d8ed;line-height:1;\">10.0<\/p>\n<p style=\"margin:0 0 20px 0;font-size:0.85em;text-transform:uppercase;letter-spacing:0.15em;color:rgba(255,255,255,0.7);\">MAXIMUM CVSS SCORE FOR CVE-2026-48558<\/p>\n<p style=\"margin:0;color:rgba(255,255,255,0.9);line-height:1.6;\">Around <strong style=\"color:#69d8ed;\">14,000<\/strong> SimpleHelp servers were exposed on the internet in June. Approximately <strong style=\"color:#69d8ed;\">7.2%<\/strong> of these were running the vulnerable OIDC configuration, per Horizon3.ai. CISA remediation deadline for federal agencies: <strong style=\"color:#69d8ed;\">July 2, 2026<\/strong>.<\/p>\n<\/div>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Attackers Introduce Two New Malware Strains<\/h2>\n<p>On June 29, Blackpoint Cyber\u2019s Adversary Pursuit Group raised the alarm. The team observed an unknown threat actor exploiting a vulnerability in a publicly accessible SimpleHelp server, hijacking a technician session, and deploying malware through it.<\/p>\n<p>Two malware families emerged for the first time in this attack. TaskWeaver is a heavily obfuscated Node.js loader disguised as a harmless <code>jquery.js<\/code> file. In the second stage, it fetches Djinn Stealer-a cross-platform infostealer targeting Windows, macOS, and Linux. A stealer on an RMM (remote monitoring and management) server is a worst-case scenario: it harvests the very credentials MSPs (managed service providers) use to access other systems.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Check Immediately If You Already Have an Unwanted Guest<\/h2>\n<p>A patch closes the door-but it won\u2019t tell you if someone already walked in. That\u2019s why you need to run a compromise check before or alongside the update. Horizon3.ai points to specific places to look.<\/p>\n<p>In the interface: Go to <code>Administration &rarr; Technicians<\/code>, click the gear icon, and enable \u201cShow Group Authenticated Users.\u201d Then review the list. Any unfamiliar name or unknown email address should set off alarms.<\/p>\n<p>In the logs: Server logs are stored under <code>Administration &rarr; Server Logs<\/code> and on the filesystem at <code>\/opt\/SimpleHelp\/logs\/server.log<\/code>, plus in dated subdirectories. Look for entries like <code>Registering technician login for [unknown-email]<\/code> and <code>Configuration save requested<\/code> tied to unfamiliar technicians. That\u2019s the calling card of a freshly created rogue session.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">What Needs to Be on Your To-Do List Now<\/h2>\n<p>Order matters. First reduce exposure, then patch properly, then clean up forensically.<\/p>\n<ul style=\"line-height:1.7;\">\n<li style=\"margin-bottom:8px;\"><strong>Patching:<\/strong> Upgrade to SimpleHelp 5.5.16, or to RC2 or the final 6.0 release in the 6.0 branch. The vendor closed the vulnerabilities back in late May.<\/li>\n<li style=\"margin-bottom:8px;\"><strong>Immediate workaround if patching stalls:<\/strong> Temporarily disable OIDC and set IP restrictions for technician logins under <code>Administration &rarr; Login Security<\/code>.<\/li>\n<li style=\"margin-bottom:8px;\"><strong>Check exposure:<\/strong> Does the RMM server really need to be exposed to the open internet? In most environments, access via VPN or a fixed IP allowlist is sufficient.<\/li>\n<li style=\"margin-bottom:8px;\"><strong>Audit accounts:<\/strong> Cross-check all technician accounts against your master list, remove any unauthorized entries, and reset their MFA registrations.<\/li>\n<li><strong>Harden processes:<\/strong> Review every authentication integration to ensure it properly validates token signatures. This vulnerability is a pattern, not an isolated case.<\/li>\n<\/ul>\n<p>For operators within the scope of NIS2 (the EU&#8217;s Network and Information Security Directive), this incident has an additional dimension. Unauthorized access to an RMM server that controls customer networks constitutes a reportable security incident. The 24-hour reporting clock starts ticking from the moment of awareness-not the end of the workday. Those who take compromise checks seriously will likely know sooner whether they need to report.<\/p>\n<p>Here is the translated HTML, adhering to all specified rules:<\/p>\n<h2 style=\"padding-top:64px;margin-bottom:20px;\">Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Each question is closed. Tap to reveal the answer.<\/p>\n<details>\n<summary><strong>Am I affected if I use SimpleHelp without OIDC?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">The bypass described here relies on OIDC login with group-based authentication. If you don\u2019t use OIDC, this specific attack path doesn\u2019t affect you. However, the update is still strongly recommended, as the patched versions close the vulnerability entirely and reduce the known attack surface.<\/p>\n<\/details>\n<details>\n<summary><strong>Is the patch enough, or do I need forensic analysis too?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">The patch prevents future unauthorized access, but it won\u2019t remove an attacker who has already gained entry. For actively exploited vulnerabilities, a compromise assessment is always essential: look for unknown technician accounts, suspicious log entries, and injected files-such as a tampered jquery.js.<\/p>\n<\/details>\n<details>\n<summary><strong>Why doesn\u2019t my enforced MFA protect me here?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">SimpleHelp allows technicians to register their own second factor during first login. An attacker exploiting the auth bypass can create a new technician identity and enroll their own MFA device. While MFA is mandatory, it doesn\u2019t protect against accounts the attacker creates themselves.<\/p>\n<\/details>\n<details>\n<summary><strong>What do TaskWeaver and Djinn Stealer have to do with this vulnerability?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">They are the payloads observed in real-world attacks. After hijacking a technician session, attackers deployed TaskWeaver-a disguised Node.js loader-that subsequently downloads Djinn Stealer. This malware harvests credentials on Windows, macOS, and Linux systems. On an RMM server, this means access to the keys for many additional systems.<\/p>\n<\/details>\n<details>\n<summary><strong>The CISA deadline was July 2. Does this affect me as a German company?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">The deadline formally applies to U.S. federal agencies under CISA\u2019s Binding Operational Directive. However, the urgency is universal: an actively exploited vulnerability with a CVSS score of 10.0 on an RMM server is a critical incident everywhere. For operators subject to NIS2 (the EU\u2019s Network and Information Security Directive), an actual breach would also trigger mandatory reporting requirements.<\/p>\n<\/details>\n<p><!--ST-LOWER-CARDS lang=en--><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">Editor\u2019s Picks<\/h3>\n<p><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/06\/25\/from-when-the-reporting-deadline-clock-really-starts-ticking\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/nis2-dora-dsgvo-meldefristen-vergleich-startpunkt-incident-cover-hero-1-250x143.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor\u2019s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">When the Incident Reporting Clock Really Starts Ticking<\/span><\/span><\/a><br \/>\n<a href=\"https:\/\/www.securitytoday.de\/en\/2026\/06\/29\/dora-in-operation-what-the-regulator-wants-to-see\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/06\/dora-finanzinstitute-resilienz-nachweis-tlpt-cover-hero-250x141.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor\u2019s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">DORA in Practice: What Regulators Want to See<\/span><\/span><\/a><br \/>\n<a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/07\/adaptive-mfa-nis2-pressure-as-a-zero-trust\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/05\/adaptive-mfa-nis2-bsi-zero-trust-mittelstand-fido2-2026-hero-250x167.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor\u2019s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Adaptive MFA: How NIS2 Pressure Is Driving Zero Trust in SMEs<\/span><\/span><\/a><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">More from the MBF Media Network<\/h3>\n<p><a href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/06\/29\/kritis-cloud-migration-c5-nis2-dachgesetz\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-kritis-cloud-migration-c5-nis2-dachgeset-70478771.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#0bb7fd;margin-bottom:5px;\">cloudmagazin<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Securing KRITIS Cloud Migration: Key Considerations<\/span><\/span><\/a><br \/>\n<a href=\"https:\/\/mybusinessfuture.com\/die-ki-aufsicht-in-deutschland-hat-jetzt-eine-adresse\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-die-ki-aufsicht-in-deutschland-hat-jetzt-91048899-250x141.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font\n<\/p>\n","protected":false},"excerpt":{"rendered":"Cybersecurity alert: SimpleHelp vulnerability CVE-2026-48558 bypasses MFA and is actively exploited. CVSS 10.0, CISA deadline, IOCs, and immediate actions.","protected":false},"author":10,"featured_media":18149,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"SimpleHelp vulnerability","_yoast_wpseo_title":"","_yoast_wpseo_metadesc":"Critical cybersecurity alert: SimpleHelp flaw CVE-2026-48558 bypasses MFA and is actively exploited. CVSS 10.0, CISA deadline, IOCs, and fixes.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_pin_until":0,"evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"en","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":[],"footnotes":""},"categories":[255],"tags":[],"class_list":["post-22572","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-praxis-umsetzung-en"],"evm_reading_time_minutes":8,"wpml_language":"en","wpml_translation_of":18102,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/22572","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=22572"}],"version-history":[{"count":1,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/22572\/revisions"}],"predecessor-version":[{"id":22573,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/22572\/revisions\/22573"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/18149"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=22572"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=22572"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=22572"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}