CVE-2024-57726Active Exploitation(simple-help / simplehelp)

HIGHCVSS 9.9 · CRITICALCISA KEV

Exploitation observed; activity peaked at 7 mentions and remains active

Immediate actions

  • Patch simple-help simplehelp systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.

7.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-05-08. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-862

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • simplehelp

Threat summary

  • Active exploitation appears in 24 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 31 mentions across 9 observed days

What's happening

  • Active exploitation reported across 24 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 20 signals
  • Disclosure: 4 classified signals
  • General: 3 classified signals
  • Peaked 5d ago at 7 mentions (2026-04-27); latest day: 1
  • 31 total mentions across 9 days

Affected systems

Products
simplehelp

Deep dive

Activity timeline31 mentions / 9d
02457Mentions · 2026-04-24: 2Mentions · 2026-04-25: 6Mentions · 2026-04-26: 4Mentions · 2026-04-27: 7Mentions · 2026-04-29: 1Mentions · 2026-04-30: 5Mentions · 2026-05-01: 2Mentions · 2026-05-04: 3Mentions · 2026-08-17: 1PoC Mentioned / Linked · 2026-04-27: 1PoC Mentioned / Linked · 2026-08-17: 1Exploit Tool / Code · 2026-04-27: 1Active Exploitation · 2026-04-24: 1Active Exploitation · 2026-04-25: 6Active Exploitation · 2026-04-26: 4Active Exploitation · 2026-04-27: 4Active Exploitation · 2026-04-29: 1Active Exploitation · 2026-04-30: 5Active Exploitation · 2026-05-04: 3Patch / Workaround · 2026-04-25: 2Patch / Workaround · 2026-04-26: 2Patch / Workaround · 2026-04-27: 1Technical Details · 2026-04-24: 2Technical Details · 2026-04-25: 3Technical Details · 2026-04-26: 2Technical Details · 2026-04-27: 5Technical Details · 2026-04-30: 4Technical Details · 2026-05-01: 1Technical Details · 2026-05-04: 2Technical Details · 2026-08-17: 104-2404-2504-2604-2704-2904-3005-0105-0408-17
Signal classification3 categories
Active Exploitation
2477.4%
Disclosure
412.9%
General
39.7%
Referenced assets28 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-242
Active Exploitation1Disclosure1
2026-04-256
Active Exploitation6
2026-04-264
Active Exploitation4
2026-04-277
Active Exploitation4Disclosure1General2
2026-04-291
Active Exploitation1
2026-04-305
Active Exploitation5
2026-05-012
Disclosure1General1
2026-05-043
Active Exploitation3
2026-08-171
Disclosure1
Full discourse20 posts
  • Dark Web Informer@DarkWebInformer
    Active Exploitation

    ‼️ Four vulnerabilities have been added to the CISA KEV Catalog CVE-2025-29635 - D-Link DIR-823X Command Injection Vulnerability CVE-2024-7399 - Samsung MagicINFO 9 Server Path Traversal Vulnerability CVE-2024-57728 - SimpleHelp Path Traversal Vulnerability CVE-2024-57726 - SimpleHelp Missing Authorization Vulnerability https://darkwebinformer.com/cisa-kev-catalog/

    Post summary

    Four CVEs have been added to the CISA KEV Catalog, confirming they are actively exploited, yet the post provides no PoC, exploit tool details, or patch information, only basic vulnerability type descriptors.

    1602175.6K
    222.6K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2024-57726 - critical 🚨 SimpleHelp <= 5.5.7 - Privilege Escalation > SimpleHelp remote support software v5.5.7 and before contains a privilege escalation ... 👾 https://cloud.projectdiscovery.io/library/CVE-2024-57726 @pdnuclei #NucleiTemplates #cve

    Post summary

    CVE-2024-57726 exposes a privilege‑escalation flaw in SimpleHelp versions 5.5.7 and earlier, with a link to related resources but no active exploitation or patch details disclosed.

    00071515
    1.3K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(4/24追加) 🛡️No.1581 CVE-2024-7399 Samsung MagicINFO 9 Server Path Traversal Vulnerability ✅概要 ・深刻度:緊急 9.8 (CVSS Base) / NVD ・種別:パス・トラバーサル (CWE-22) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Samsung MagicINFO 9 Server 21.1050未満において、制限されたディレクトリ外へのパス操作により、事前認証されていない攻撃者が任意のファイルをsystem authorityに書き込まれる恐れがある。Arctic Wolfの報告では、細工したJSPファイルのアップロードによりリモートコード実行に至る可能性がある。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅攻撃前提条件 ・Samsung MagicINFO 9 Server 21.1050未満が稼働していること。 ・攻撃者が対象サーバへネットワーク越しに到達可能であること。 ・認証は不要。 ✅悪用時影響 ・任意のファイルを書き込まれる ・system authorityでファイルを書き込まれる ・細工したJSPファイルを配置された場合、リモートコードの実行 ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開済み ・ITW:確認済み。Arctic Wolfは、2025年5月初旬に本脆弱性の実環境での悪用を観測したと報告。 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2024-7399 https://security.samsungtv.com/securityUpdates https://davidxbors.github.io/0xpages/posts/cve-2024-7399/ https://arcticwolf.com/resources/blog/cve-2024-7399/ 🛡️No.1582 CVE-2024-57726 SimpleHelp Missing Authorization Vulnerability ✅概要 ・深刻度:緊急 9.9 (CVSS Base) / NVD ・種別:認証の欠如 (CWE-862) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H SimpleHelp remote support software において、低権限の technician が過剰な権限を持つ API key を作成でき、その API key を用いて server admin 権限昇格される恐れがある。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅攻撃前提条件 ・SimpleHelp の脆弱バージョンが稼働していること。 ・攻撃者が低権限の technician アカウントを有していること。 ・攻撃者が対象サーバへネットワーク越しに到達可能であること。 ✅悪用時影響 ・過剰な権限を持つ API key を作成される可能性がある。 ・server admin 権限へ昇格される可能性がある。 ・管理者化により、低権限 technician が本来アクセスできない接続先 client machine にアクセスされる可能性がある。 ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み。Microsoft は Storm-1175 が CVE-2024-57726 を含む SimpleHelp の脆弱性を悪用していたと報告し、Trend Micro も DragonForce が CVE-2024-57726 を悪用して低権限ユーザーから管理者アクセスを得ていたと報告。 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2024-57726 https://guides.simple-help.com/kb---security-vulnerabilities-01-2025 https://horizon3.ai/attack-research/disclosures/critical-vulnerabilities-in-simplehelp-remote-support-software/ https://www.microsoft.com/en-us/security/blog/2026/04/06/storm-1175-focuses-gaze-on-vulnerable-web-facing-assets-in-high-tempo-medusa-ransomware-operations/ 🛡️No.1583 CVE-2024-57728 SimpleHelp Path Traversal Vulnerability ✅概要 ・深刻度:重要 7.2 (CVSS Base) / NVD (NVD) ・種別:リンク解釈の問題 (CWE-59) (NVD) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H (NVD) SimpleHelp remote support software v5.5.7以前において、管理者ユーザーが細工されたZIPファイルをアップロードすることで、ファイルシステム上の任意の場所へファイルを書き込まれる恐れがある。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅攻撃前提条件 ・SimpleHelp v5.5.7以前の脆弱バージョンが稼働していること。 ・攻撃者が管理者ユーザー、または管理者権限を持つtechnicianとしてログイン可能であること。 ・細工されたZIPファイルをアップロードできること。 ✅悪用時影響 ・ファイルシステム上の任意の場所にファイルを書き込まれる可能性がある。 ・SimpleHelpサーバーユーザー権限で任意コード実行に至る可能性がある。 ・Linuxサーバではcrontabファイルの配置、WindowsサーバではSimpleHelpが使用する実行ファイルやライブラリの上書きにより悪用される可能性がある。 ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み。Trend Microは、DragonForceがSimpleHelpの脆弱性としてCVE-2024-57728をラテラルムーブメントや情報収集に悪用していたと報告。 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2024-57728 https://simple-help.com/kb---security-vulnerabilities-01-2025#security-vulnerabilities-in-simplehelp-5-5-7-and-earlier https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-dragonforce 🛡️No.1584 CVE-2025-29635 D-Link DIR-823X Command Injection Vulnerability ✅概要 ・深刻度:重要 7.2 (CVSS Base) / CISA-ADP (NVD) ・種別:コマンドインジェクション (CWE-77) (NVD) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H (NVD) D-Link DIR-823X ファームウェア 240126 および 240802 には、/goform/set_prohibiting への POST リクエストを通じて任意のコマンドを実行される恐れがある。 対象機器の DIR-823X は、D-Link により EOL/EOS とされており、D-Link は停止と置き換えを推奨。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:高 ✅攻撃前提条件 ・D-Link DIR-823X のファームウェア 240126 または 240802 が稼働していること。 ・攻撃者が対象機器へネットワーク越しに到達可能であること。 ・認証済みの攻撃者であること。 ✅悪用時影響 ・リモートで任意のコマンドを実行される可能性がある。 ・機密性、完全性、可用性に高い影響が生じる可能性がある。 ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み。Akamai SIRT は、2026年3月初旬にグローバルなハニーポット網でこの脆弱性の悪用を確認し、Mirai 亜種の展開に使われていると報告。 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-29635 https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10469 https://www.akamai.com/blog/security-research/cve-2025-29635-mirai-campaign-targets-d-link-devices https://www.cisa.gov/news-events/alerts/2026/04/24/cisa-adds-four-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    The tweet reports that four CVEs have been added to CISA’s Exploited Vulnerabilities catalog after confirmation of in‑the‑wild exploitation, with publicly available PoCs and detailed technical data.

    000415.0K
    43.6K followersView on X
  • Elusive@ElusivePrivacy
    Active Exploitation

    📋CISA added four actively exploited vulnerabilities to the KEV catalog: 🔸CVE-2024-57726 / CVE-2024-57728 — SimpleHelp (privilege escalation + path traversal, linked to DragonForce ransomware) 🔸CVE-2024-7399 — Samsung MagicINFO 9 Server path traversal (Mirai delivery observed) 🔸CVE-2025-29635 — D-Link DIR-823X command injection (EOL device, no patch retire it) Federal deadline: May 8, 2026. 📄 Source: CISA 👉 Follow @VulnerabilityNw — full catalog coverage on our Telegram → http://t.me/VulnerabilityNews

    Post summary

    CISA has listed CVE‑2024‑57726/57728, CVE‑2024‑7399, and CVE‑2025‑29635 as actively exploited, noting privilege escalation, path traversal, and command‑injection weaknesses used by ransomware and Mirai, with a federal patch deadline of May 8 2026.

    11020161
    185 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    06:05 UTC: CVE-2024-57726 disclosed. The Four-CVE KEV Cluster: How DragonForce and Mirai Turned CISA's April 24 Drop Into a Live Ransomware-and-Botnet Race

    Post summary

    CVE‑2024‑57726 was publicly disclosed, and according to the CISA KEV report, botnets DragonForce and Mirai are actively exploiting it in a live ransomware and botnet competition.

    1002068
    308 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2024-32002 2 - CVE-2025-20333 3 - CVE-2026-20131 4 - CVE-2026-33626 5 - CVE-2024-57726 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The snippet lists trending CVEs without providing any technical details, exploit information, or mitigation guidance, thus it serves as a general trend announcement.

    00021725
    1.7K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    09:05 UTC: First exploit attempt in the wild. On April 24, 2026, CISA added four CVEs to its Known Exploited Vulnerabilities catalog spanning three products: SimpleHelp (CVE-2024-57726, CVSS 9.9 and CVE-2024-57728, CVSS 7.2), Samsung MagicINFO 9 Server (CVE-2024-7399,…

    Post summary

    The report confirms the first real‑world exploitation attempts for four CVEs, with CISA identifying them in its Known Exploited Vulnerabilities catalog.

    1001055
    128 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    06:19 UTC: Thread live on @lyrie_ai. On April 24, 2026, CISA added four CVEs to its Known Exploited Vulnerabilities catalog spanning three products: SimpleHelp (CVE-2024-57726, CVSS 9.9 and CVE-2024-57728, CVSS 7.2), Samsung MagicINFO 9 Server (CVE-2024-7399, CVSS 8.8),…

    Post summary

    CISA identified four CVEs—including SimpleHelp and Samsung MagicINFO—as actively exploited in the wild, providing CVSS scores, but no proof of concept, exploit code, or patch information is offered.

    2000044
    128 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    What happened CISA added CVE-2024-57726 to its Known Exploited Vulnerabilities catalog on 2026-04-24, triggering mandatory remediation for U.S. federal civilian agencies under BOD 22-01 CISA KEV. The vulnerability is a missing authorization flaw in SimpleHelp that allows a…

    Post summary

    CISA has listed CVE-2024-57726 as a known exploited vulnerability requiring mandatory remediation for U.S. federal civilian agencies. The post provides a brief technical description but no PoC, exploit code, or patch details.

    1000037
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2024-57726: CISA KEV: SimpleHelp missing authorization lets low-priv techs mint over-privileged API keys and escalate to server admin. What happened CISA added CVE-2024-57726 to its Known Exploited Vulnerabilities catalog on 2026-04-24, triggering mandatory…

    Post summary

    The CVE‑2024‑57726 is actively exploited, as noted by its inclusion in CISA’s KEV catalog, allowing low‑privileged users in SimpleHelp to create over‑privileged API keys and gain server admin rights.

    1000040
    152 followersView on X
  • Inferlume@inferlume_hq
    General

    Priority order for today. cPanel CVE-2026-41940. SimpleHelp CVE-2024-57726 and CVE-2024-57728. Windows Shell CVE-2026-32202. ActiveMQ CVE-2026-34197. Linux Copy Fail CVE-2026-31431. Samsung MagicINFO CVE-2024-7399. D-Link DIR-823X CVE-2025-29635.

    Post summary

    The text lists a series of CVEs without providing any additional context such as proof of concept, exploits, patches, or technical details.

    100001.0K
    1 followersView on X
  • Inferlume@inferlume_hq
    Disclosure

    CVE-2024-57726 in SimpleHelp. CVSS 9.9. Any technician account can generate admin-level API keys. No authorization check. When chained with CVE-2024-57728 zip-slip RCE, you get full server takeover from a single low-privilege credential. Federal deadline 8 May 2026.

    Post summary

    The post discloses a high‑severity (CVSS 9.9) vulnerability in SimpleHelp that allows technician accounts to create admin‑level API keys and, when combined with CVE‑2024‑57728, enables full server takeover from a low‑privilege credential; no patches or exploit code are mentioned.

    1000047
    1 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    06:08 UTC: Lyrie Sentinel flagged it. On April 24, 2026, CISA added four CVEs to its Known Exploited Vulnerabilities catalog spanning three products: SimpleHelp (CVE-2024-57726, CVSS 9.9 and CVE-2024-57728, CVSS 7.2), Samsung MagicINFO 9 Server (CVE-2024-7399, CVSS 8.8),…

    Post summary

    CISA has flagged four CVEs as known exploited vulnerabilities across three products, highlighting active cyber‑attack use, though no detailed exploit or PoC is supplied and no remediation is referenced.

    1000032
    128 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    06:16 UTC: GPT-5 enrichment complete. 2,249 words. 0 citations. On April 24, 2026, CISA added four CVEs to its Known Exploited Vulnerabilities catalog spanning three products: SimpleHelp (CVE-2024-57726, CVSS 9.9 and CVE-2024-57728, CVSS 7.2), Samsung MagicINFO 9 Server…

    Post summary

    CISA confirmed that CVE-2024-57726 and CVE-2024-57728 are actively exploited, as evidenced by their inclusion in the Known Exploited Vulnerabilities catalog.

    1000038
    128 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2024-57726 Lyrie Threat Intelligence is flagging a convergence across four recent, actively exploited advisories that map cleanly to CISA KEV prioritization logic: two SimpleHelp server vulnerabilities, one Samsung MagicINFO 9 Server issue, and a D-Link DIR‑823x…

    Post summary

    The post highlights CVE-2024-57726 as part of a group of actively exploited advisories aligned with CISA KEV prioritization, signaling real‑world exploitation but lacking detailed technical or PoC information.

    1000034
    125 followersView on X
  • Inferlume@inferlume_hq
    Disclosure

    SimpleHelp CVE-2024-57726 scores CVSS 9.9 and has been linked to DragonForce ransomware precursor activity. D-Link DIR-823X has no patch. It is end of life. CISA says to discontinue the device entirely.

    Post summary

    The post reports a new vulnerability (CVE-2024-57726) with a high CVSS score of 9.9, notes its association with DragonForce ransomware precursor activity, and advises discontinuing the end‑of‑life D‑Link DIR‑823X due to lack of patch.

    1000046
    1 followersView on X
  • Inferlume@inferlume_hq
    General

    CISA added four CVEs to KEV on 24 April 2026: CVE-2024-57726 and CVE-2024-57728 in SimpleHelp, CVE-2024-7399 in Samsung MagicINFO 9, and CVE-2025-29635 in D-Link DIR-823X. Federal deadline is 8 May 2026.

    Post summary

    CISA announced four CVEs added to its KEV list and set a federal deadline for remediation.

    10000574
    1 followersView on X
  • SecureChap@SecureChap
    Active Exploitation

    3,500 SimpleHelp servers sat on the public internet in January 2025. CISA just confirmed they've been getting chained by ransomware groups for over a year. Three CVEs from January 2025 - CVE-2024-57727, 57726, and 57728 - disclosed by Naveen Sunkavally at http://Horizon3.ai and patched in SimpleHelp 5.5.8, 5.4.10, and 5.3.9. The chain: an unauthenticated path traversal pulls serverconfig.xml off the box, leaking hashed technician passwords. Crack one and log in as a low-privileged tech. Then a missing authorization check on the admin API lets a crafted request sequence mint an API key with full admin role. From admin, the file upload endpoint accepts a ZIP that path-traverses out of its target directory - swap a Windows DLL or drop a Linux crontab and you have RCE. First in-the-wild exploitation: January 22, 2025. Sliver backdoors. Medusa picked it up on February 6, followed by INC Ransom and RansomHub. Still active into 2026. CISA added the two SimpleHelp CVEs (CVE-2024-57726 at CVSS 9.9 and CVE-2024-57728) to KEV on April 24-25, 2026. Federal deadline to patch: May 8. SimpleHelp is the box your MSP uses to remote into your endpoints. Owning it hands an attacker the same access the technicians have - to every customer they support.

    Post summary

    The post reports that 3,500 SimpleHelp servers were compromised via three CVEs, with active ransomware exploitation in the wild since January 2025 and ongoing into 2026, while patches are available and a CISA KEV has been issued.

    0100052
    6 followersView on X
  • Inferlume@inferlume_hq
    Active Exploitation

    SimpleHelp CVE-2024-57726. CVSS 9.9. Any technician account creates admin API keys and escalates to server admin. CISA KEV April 24. Ransomware confirmed in production. CVE-2024-57728 adds host RCE. Patch above v5.5.7 now.

    Post summary

    The tweet indicates that SimpleHelp CVEs 2024-57726 and 2024-57728 are actively exploited in the wild, with ransomware confirmed in production, and a patch is available above version 5.5.7.

    1000052
    1 followersView on X
  • abhishek gautam@Abhs_tweets
    Active Exploitation

    Key facts: → CISA added 4 CVEs on April 24, 2026: SimpleHelp (CVSS 9.9 + 7.2), Samsung MagicINFO 9 (CVSS 8.8), D-Link DIR-823X (CVSS 7.5); federal FCEB agencies must patch or discontinue by May 8 → CVE-2024-57726 is the critical one: technician-to-admin escalation with no additional authentication; DragonForce ransomware using it as MSP fleet attack precursor

    Post summary

    CISA identifies four CVEs, including the critical CVE-2024-57726, which is actively leveraged by DragonForce ransomware as an MSP fleet attack precursor; federal agencies are required to patch or discontinue systems by May 8.

    1000050
    32 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsimple-helpsimplehelp---

Explore more