CVE-2024-57727Active Exploitation(simple-help / simplehelp)

MEDIUMCVSS 7.5 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch simple-help simplehelp systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-03-06. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-22

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • simplehelp

Threat summary

  • Active exploitation appears in 4 classified signals
  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 4 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 4d ago at 1 mentions (2026-02-20); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Products
simplehelp

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-02-20: 1Mentions · 2026-03-09: 1Mentions · 2026-04-08: 1Mentions · 2026-04-27: 1Mentions · 2026-06-15: 1Active Exploitation · 2026-02-20: 1Active Exploitation · 2026-04-08: 1Active Exploitation · 2026-04-27: 1Active Exploitation · 2026-06-15: 1Patch / Workaround · 2026-04-27: 1Patch / Workaround · 2026-06-15: 1Technical Details · 2026-02-20: 1Technical Details · 2026-04-27: 102-2003-0904-0804-2706-15
Signal classification2 categories
Active Exploitation
480.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-201
Active Exploitation1
2026-03-091
General1
2026-04-081
Active Exploitation1
2026-04-271
Active Exploitation1
2026-06-151
Active Exploitation1
Full discourse5 posts
  • Team Cymru Research@teamcymru_S2
    Active Exploitation

    🚨 Top 25 CVE Exploitation Attempts - Team Cymru - S2 (Ranked by unique source IPs over 14 days) 1. CVE-2025-0282 · Ivanti Connect Secure 2. CVE-2025-49706 · SharePoint 3. CVE-2020-3452 · Cisco ASA 4. CVE-2025-61884 · Oracle EBS 5. CVE-2024-32113 · Apache OFBiz 6. CVE-2025-53770 · SharePoint 7. CVE-2025-24893 · XWiki 8. CVE-2025-61882 · Oracle EBS 9. CVE-2025-5777 · Citrix NetScaler 10. CVE-2025-34028 · Commvault 11. CVE-2024-57727 · SimpleHelp 12. CVE-2025-20362 · Cisco ASA/FTD 13. CVE-2024-1212 · Kemp LoadMaster 14. CVE-2024-38856 · Apache OFBiz 15. CVE-2022-40684 · Fortinet 16. CVE-2024-9465 · Palo Alto Expedition 17. CVE-2025-11371 · Gladinet CentreStack 18. CVE-2025-58360 · GeoServer 19. CVE-2025-57819 · FreePBX 20. CVE-2025-31324 · SAP NetWeaver 21. CVE-2024-7593 · Ivanti vTM 22. CVE-2025-31125 · Vite Dev Server 23. CVE-2025-64446 · FortiWeb 24. CVE-2024-12987 · DrayTek Vigor 25. CVE-2018-7600 · Drupal

    Post summary

    Team Cymru reports the top 25 CVE exploitation attempts over a 14‑day period, indicating these vulnerabilities are actively being leveraged in the wild.

    070921.2K
    5.5K followersView on X
  • SecureChap@SecureChap
    Active Exploitation

    3,500 SimpleHelp servers sat on the public internet in January 2025. CISA just confirmed they've been getting chained by ransomware groups for over a year. Three CVEs from January 2025 - CVE-2024-57727, 57726, and 57728 - disclosed by Naveen Sunkavally at http://Horizon3.ai and patched in SimpleHelp 5.5.8, 5.4.10, and 5.3.9. The chain: an unauthenticated path traversal pulls serverconfig.xml off the box, leaking hashed technician passwords. Crack one and log in as a low-privileged tech. Then a missing authorization check on the admin API lets a crafted request sequence mint an API key with full admin role. From admin, the file upload endpoint accepts a ZIP that path-traverses out of its target directory - swap a Windows DLL or drop a Linux crontab and you have RCE. First in-the-wild exploitation: January 22, 2025. Sliver backdoors. Medusa picked it up on February 6, followed by INC Ransom and RansomHub. Still active into 2026. CISA added the two SimpleHelp CVEs (CVE-2024-57726 at CVSS 9.9 and CVE-2024-57728) to KEV on April 24-25, 2026. Federal deadline to patch: May 8. SimpleHelp is the box your MSP uses to remote into your endpoints. Owning it hands an attacker the same access the technicians have - to every customer they support.

    Post summary

    Reports ongoing in-the-wild exploitation of 3 SimpleHelp CVEs via path traversal and RCE, provides detailed technical descriptions, and indicates patch availability, but no PoC or exploit code is presented.

    0100052
    6 followersView on X
  • ScruteX@scrutexai
    Active Exploitation

    What to patch first, tied to this week's active groups: Fortinet CVE-2024-21762, CVE-2024-55591 (Qilin) SimpleHelp CVE-2024-57727 (DragonForce) VMware ESXi CVE-2024-37085 (Akira) Citrix CVE-2023-3519 (INC Ransom) Full report: https://scrutex.ai/blogs/weekly-ransomware-intelligence-report-june-14-2026 #ransomware #threatintel #CTEM

    Post summary

    Several CVEs across Fortinet, SimpleHelp, VMware ESXi, and Citrix are being targeted by active ransomware groups, underscoring the urgency of patching them.

    00000107
    83 followersView on X
  • 317ON13_LIRW@ToTo13ru_xakep
    General

    I just completed SimpleHelp: CVE-2024-57727 room on TryHackMe! Learn how attackers can exploit CVE-2024-57727 and how to detect that. https://tryhackme.com/room/simplehelpcve202457727?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=662fb6411f3680a87baf9e1f #tryhackme via @tryhackme

    Post summary

    A user posts that they completed a TryHackMe room on CVE‑2024‑57727, indicating the room includes lessons on exploitation and detection, but provides no technical, exploit, or patch details.

    0000032
  • RST Cloud@rst_cloud
    Active Exploitation

    #threatreport #LowCompleteness Brand Trust as a Weapon: Multi-Brand Impersonation Campaigns Deliver JWrapper Malware | 19-02-2026 Source: https://cofense.com/blog/brand-trust-as-a-weapon-multi-brand-impersonation-campaigns-deliver-jwrapper-malware Key details below ↓ 💀Threats: Simplehelp_tool, 🎯Victims: Docusign users, Simplehelp users 🔓CVEs: CVE-2024-57727 \[[Vulners](https://vulners.com/cve/CVE-2024-57727)] - CVSS V3.1: *9.1*, - Vulners: Exploitation: True Soft: - simple-help simplehelp (<5.5.8) 📚TTPs: ⚔️Tactics: 1 🛠️Technics: 0 🤖LLM extracted TTPs:` T1036, T1105, T1204.002, T1566.001, T1566.002 🧨IOCs: - Url: 9 - IP: 10 - Hash: 3 💽Software: JWrapper, Zoom 🔢Algorithms: md5, sha256 📜Programming Languages: java 💻Platforms: cross-platform #threatreport: Recent cyber threat campaigns have exploited the trust associated with well-known brands, specifically targeting DocuSign and SimpleHelp to distribute JWrapper malware. Attackers create fraudulent communications that appear legitimate to trick users into executing harmful software. These campaigns incorporate malicious executables disguised within documents or download links that impersonate the trusted brands. The malware delivery mechanism relies heavily on JWrapper, a Java-based installer framework that packages the required Java Virtual Machine (JVM) along with application files, creating a single executable that functions across different operating systems. Although JWrapper assists in the delivery and installation of malware, the actual remote access capability is primarily provided by the SimpleHelp Remote Monitoring and Management (RMM) tool. This dual-hardware approach, combining JWrapper and SimpleHelp, allows attackers to maintain stealth and persistence during their intrusions. SimpleHelp, originally a legitimate tool used by IT teams, has become a preferred choice among threat actors due to its ability to facilitate control over compromised systems discreetly. The Cofense Phishing Defense Center's analysis underscores the importance of identifying indicators of such intrusions. Organizations should enhance their detection capabilities to recognize anomalies associated with SimpleHelp installations and monitor for unusual remote access activity. By understanding the tactics used in these attacks, defenders can improve their response strategies to mitigate the risks posed by this evolving threat landscape.

    Post summary

    CVE‑2024‑57727 is being actively exploited in recent campaigns targeting DocuSign and SimpleHelp via a JWrapper‑based delivery chain, with attackers using SimpleHelp RMM for remote control.

    0000077
    583 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsimple-helpsimplehelp---

Explore more