CVE-2024-57728Active Exploitation(simple-help / simplehelp)

HIGHCVSS 7.2 · HIGHCISA KEV

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch simple-help simplehelp systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.

7.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-05-08. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-59CWE-22

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • simplehelp

Threat summary

  • Active exploitation appears in 21 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 29 mentions across 10 observed days

What's happening

  • Active exploitation reported across 21 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 20 signals
  • General: 4 classified signals
  • Disclosure: 3 classified signals
  • Peaked 8d ago at 5 mentions (2026-04-25); latest day: 1
  • 29 total mentions across 10 days

Affected systems

Products
simplehelp

Deep dive

Activity timeline29 mentions / 10d
01345Mentions · 2026-04-24: 2Mentions · 2026-04-25: 5Mentions · 2026-04-26: 2Mentions · 2026-04-27: 5Mentions · 2026-04-30: 5Mentions · 2026-05-01: 2Mentions · 2026-05-03: 1Mentions · 2026-05-04: 5Mentions · 2026-05-23: 1Mentions · 2026-09-24: 1PoC Mentioned / Linked · 2026-04-27: 1PoC Mentioned / Linked · 2026-05-04: 1Exploit Tool / Code · 2026-04-27: 2Active Exploitation · 2026-04-25: 5Active Exploitation · 2026-04-26: 2Active Exploitation · 2026-04-27: 5Active Exploitation · 2026-04-30: 5Active Exploitation · 2026-05-04: 4Patch / Workaround · 2026-04-25: 1Patch / Workaround · 2026-04-26: 2Patch / Workaround · 2026-04-27: 1Patch / Workaround · 2026-04-30: 1Patch / Workaround · 2026-05-03: 1Patch / Workaround · 2026-05-04: 1Technical Details · 2026-04-24: 1Technical Details · 2026-04-25: 2Technical Details · 2026-04-26: 2Technical Details · 2026-04-27: 4Technical Details · 2026-04-30: 4Technical Details · 2026-05-01: 1Technical Details · 2026-05-03: 1Technical Details · 2026-05-04: 3Technical Details · 2026-05-23: 1Technical Details · 2026-09-24: 104-2404-2504-2604-2704-3005-0105-0305-0405-2309-24
Signal classification4 categories
Active Exploitation
2069.0%
General
413.8%
Disclosure
310.3%
Patch
26.9%
Referenced assets27 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-242
Disclosure1General1
2026-04-255
Active Exploitation5
2026-04-262
Active Exploitation2
2026-04-275
Active Exploitation5
2026-04-305
Active Exploitation5
2026-05-012
Disclosure1General1
2026-05-031
Patch1
2026-05-045
Active Exploitation3General1Patch1
2026-05-231
General1
2026-09-241
Disclosure1
Full discourse20 posts
  • Dark Web Informer@DarkWebInformer
    General

    ‼️ Four vulnerabilities have been added to the CISA KEV Catalog CVE-2025-29635 - D-Link DIR-823X Command Injection Vulnerability CVE-2024-7399 - Samsung MagicINFO 9 Server Path Traversal Vulnerability CVE-2024-57728 - SimpleHelp Path Traversal Vulnerability CVE-2024-57726 - SimpleHelp Missing Authorization Vulnerability https://darkwebinformer.com/cisa-kev-catalog/

    Post summary

    The message notes that four CVEs were added to the CISA KEV catalog, listing them with basic type descriptors, without providing PoCs, exploits, patches, or detailed technical information.

    1602175.6K
    222.6K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(4/24追加) 🛡️No.1581 CVE-2024-7399 Samsung MagicINFO 9 Server Path Traversal Vulnerability ✅概要 ・深刻度:緊急 9.8 (CVSS Base) / NVD ・種別:パス・トラバーサル (CWE-22) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Samsung MagicINFO 9 Server 21.1050未満において、制限されたディレクトリ外へのパス操作により、事前認証されていない攻撃者が任意のファイルをsystem authorityに書き込まれる恐れがある。Arctic Wolfの報告では、細工したJSPファイルのアップロードによりリモートコード実行に至る可能性がある。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅攻撃前提条件 ・Samsung MagicINFO 9 Server 21.1050未満が稼働していること。 ・攻撃者が対象サーバへネットワーク越しに到達可能であること。 ・認証は不要。 ✅悪用時影響 ・任意のファイルを書き込まれる ・system authorityでファイルを書き込まれる ・細工したJSPファイルを配置された場合、リモートコードの実行 ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開済み ・ITW:確認済み。Arctic Wolfは、2025年5月初旬に本脆弱性の実環境での悪用を観測したと報告。 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2024-7399 https://security.samsungtv.com/securityUpdates https://davidxbors.github.io/0xpages/posts/cve-2024-7399/ https://arcticwolf.com/resources/blog/cve-2024-7399/ 🛡️No.1582 CVE-2024-57726 SimpleHelp Missing Authorization Vulnerability ✅概要 ・深刻度:緊急 9.9 (CVSS Base) / NVD ・種別:認証の欠如 (CWE-862) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H SimpleHelp remote support software において、低権限の technician が過剰な権限を持つ API key を作成でき、その API key を用いて server admin 権限昇格される恐れがある。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅攻撃前提条件 ・SimpleHelp の脆弱バージョンが稼働していること。 ・攻撃者が低権限の technician アカウントを有していること。 ・攻撃者が対象サーバへネットワーク越しに到達可能であること。 ✅悪用時影響 ・過剰な権限を持つ API key を作成される可能性がある。 ・server admin 権限へ昇格される可能性がある。 ・管理者化により、低権限 technician が本来アクセスできない接続先 client machine にアクセスされる可能性がある。 ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み。Microsoft は Storm-1175 が CVE-2024-57726 を含む SimpleHelp の脆弱性を悪用していたと報告し、Trend Micro も DragonForce が CVE-2024-57726 を悪用して低権限ユーザーから管理者アクセスを得ていたと報告。 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2024-57726 https://guides.simple-help.com/kb---security-vulnerabilities-01-2025 https://horizon3.ai/attack-research/disclosures/critical-vulnerabilities-in-simplehelp-remote-support-software/ https://www.microsoft.com/en-us/security/blog/2026/04/06/storm-1175-focuses-gaze-on-vulnerable-web-facing-assets-in-high-tempo-medusa-ransomware-operations/ 🛡️No.1583 CVE-2024-57728 SimpleHelp Path Traversal Vulnerability ✅概要 ・深刻度:重要 7.2 (CVSS Base) / NVD (NVD) ・種別:リンク解釈の問題 (CWE-59) (NVD) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H (NVD) SimpleHelp remote support software v5.5.7以前において、管理者ユーザーが細工されたZIPファイルをアップロードすることで、ファイルシステム上の任意の場所へファイルを書き込まれる恐れがある。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅攻撃前提条件 ・SimpleHelp v5.5.7以前の脆弱バージョンが稼働していること。 ・攻撃者が管理者ユーザー、または管理者権限を持つtechnicianとしてログイン可能であること。 ・細工されたZIPファイルをアップロードできること。 ✅悪用時影響 ・ファイルシステム上の任意の場所にファイルを書き込まれる可能性がある。 ・SimpleHelpサーバーユーザー権限で任意コード実行に至る可能性がある。 ・Linuxサーバではcrontabファイルの配置、WindowsサーバではSimpleHelpが使用する実行ファイルやライブラリの上書きにより悪用される可能性がある。 ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み。Trend Microは、DragonForceがSimpleHelpの脆弱性としてCVE-2024-57728をラテラルムーブメントや情報収集に悪用していたと報告。 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2024-57728 https://simple-help.com/kb---security-vulnerabilities-01-2025#security-vulnerabilities-in-simplehelp-5-5-7-and-earlier https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-dragonforce 🛡️No.1584 CVE-2025-29635 D-Link DIR-823X Command Injection Vulnerability ✅概要 ・深刻度:重要 7.2 (CVSS Base) / CISA-ADP (NVD) ・種別:コマンドインジェクション (CWE-77) (NVD) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H (NVD) D-Link DIR-823X ファームウェア 240126 および 240802 には、/goform/set_prohibiting への POST リクエストを通じて任意のコマンドを実行される恐れがある。 対象機器の DIR-823X は、D-Link により EOL/EOS とされており、D-Link は停止と置き換えを推奨。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:高 ✅攻撃前提条件 ・D-Link DIR-823X のファームウェア 240126 または 240802 が稼働していること。 ・攻撃者が対象機器へネットワーク越しに到達可能であること。 ・認証済みの攻撃者であること。 ✅悪用時影響 ・リモートで任意のコマンドを実行される可能性がある。 ・機密性、完全性、可用性に高い影響が生じる可能性がある。 ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み。Akamai SIRT は、2026年3月初旬にグローバルなハニーポット網でこの脆弱性の悪用を確認し、Mirai 亜種の展開に使われていると報告。 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-29635 https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10469 https://www.akamai.com/blog/security-research/cve-2025-29635-mirai-campaign-targets-d-link-devices https://www.cisa.gov/news-events/alerts/2026/04/24/cisa-adds-four-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA added several CVEs to its exploited catalog, confirming that these vulnerabilities are being abused in the wild and that PoCs have been publicly released.

    000415.0K
    43.6K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2024-57728 - high 🚨 SimpleHelp <= 5.5.7 - Arbitrary File Upload > SimpleHelp remote support software v5.5.7 and before allows admin users to upload arb... 👾 https://cloud.projectdiscovery.io/library/CVE-2024-57728 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces CVE-2024-57728 as an arbitrary file upload vulnerability in SimpleHelp v5.5.7 and before, providing technical context and a link to a ProjectDiscovery library entry without confirming a patch, PoC, or active exploitation.

    00031297
    1.3K followersView on X
  • Elusive@ElusivePrivacy
    Active Exploitation

    📋CISA added four actively exploited vulnerabilities to the KEV catalog: 🔸CVE-2024-57726 / CVE-2024-57728 — SimpleHelp (privilege escalation + path traversal, linked to DragonForce ransomware) 🔸CVE-2024-7399 — Samsung MagicINFO 9 Server path traversal (Mirai delivery observed) 🔸CVE-2025-29635 — D-Link DIR-823X command injection (EOL device, no patch retire it) Federal deadline: May 8, 2026. 📄 Source: CISA 👉 Follow @VulnerabilityNw — full catalog coverage on our Telegram → http://t.me/VulnerabilityNews

    Post summary

    CISA identified four vulnerabilities that are actively exploited, listing CVE details and attack vectors such as privilege escalation, path traversal, and command injection, and noting the absence of a patch for an EOL D-Link device.

    11020161
    185 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    09:05 UTC: First exploit attempt in the wild. On April 24, 2026, CISA added four CVEs to its Known Exploited Vulnerabilities catalog spanning three products: SimpleHelp (CVE-2024-57726, CVSS 9.9 and CVE-2024-57728, CVSS 7.2), Samsung MagicINFO 9 Server (CVE-2024-7399,…

    Post summary

    CISA confirms the first in‑the‑wild exploitation of four CVEs affecting SimpleHelp and Samsung MagicINFO 9 Server, underscoring active attacks on these products.

    1001055
    128 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    06:19 UTC: Thread live on @lyrie_ai. On April 24, 2026, CISA added four CVEs to its Known Exploited Vulnerabilities catalog spanning three products: SimpleHelp (CVE-2024-57726, CVSS 9.9 and CVE-2024-57728, CVSS 7.2), Samsung MagicINFO 9 Server (CVE-2024-7399, CVSS 8.8),…

    Post summary

    CISA has identified and cataloged four high‑CVSS CVEs as Known Exploited Vulnerabilities, indicating they are actively leveraged in the wild.

    2000044
    128 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    What happened CISA added CVE-2024-57728 to its Known Exploited Vulnerabilities (KEV) catalog on 2026-04-24, signaling active exploitation in the wild CISA KEV. The entry covers a SimpleHelp server flaw tracked as a path traversal (CWE-22) “zip slip” issue that enables…

    Post summary

    CISA has listed CVE‑2024‑57728 in its Known Exploited Vulnerabilities catalog, indicating that path‑traversal "zip‑slip" attacks on SimpleHelp servers are occurring in the wild.

    1000038
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2024-57728: Zip-slip path traversal in SimpleHelp lets an admin write files anywhere and achieve code execution as the SimpleHelp server user. Now in CISA KEV.

    Post summary

    CVE‑2024‑57728 is a path‑traversal flaw in SimpleHelp that lets an admin write arbitrary files and execute code. Its inclusion in the CISA KEV list signals that it is considered a high‑risk vulnerability, potentially already exploited in the wild.

    1000038
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    Defense CISA mandates remediation or mitigations by 2026-05-08: apply vendor fixes, follow BOD 22-01 guidance for cloud services, or discontinue use if mitigations aren’t available CISA KEV. Prioritize patching for all instances of SimpleHelp covered by CVE-2024-57728 and…

    Post summary

    CISA mandates remediation of CVE-2024-57728 in SimpleHelp by 2026-05-08, urging vendor fixes or BOD 22‑01 mitigations and highlighting the CVE as a known exploited vulnerability.

    1000044
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Technical detail CVE-2024-57728 is categorized as a path traversal (CWE-22) that manifests during ZIP archive handling (“zip slip”) NVD entry. The vulnerable flow allows an authenticated SimpleHelp administrator to upload a crafted ZIP whose entries contain traversal…

    Post summary

    The excerpt provides a concise technical description of CVE‑2024‑57728 as a path‑traversal (zip slip) flaw, but makes no mention of PoC, exploitation, patch, or false positive.

    1000035
    152 followersView on X
  • Inferlume@inferlume_hq
    General

    Priority order for today. cPanel CVE-2026-41940. SimpleHelp CVE-2024-57726 and CVE-2024-57728. Windows Shell CVE-2026-32202. ActiveMQ CVE-2026-34197. Linux Copy Fail CVE-2026-31431. Samsung MagicINFO CVE-2024-7399. D-Link DIR-823X CVE-2025-29635.

    Post summary

    A brief list of CVE identifiers for today’s priority focus, with no additional detail on exploitation, mitigation or technical specifics.

    100001.0K
    1 followersView on X
  • Inferlume@inferlume_hq
    Disclosure

    CVE-2024-57726 in SimpleHelp. CVSS 9.9. Any technician account can generate admin-level API keys. No authorization check. When chained with CVE-2024-57728 zip-slip RCE, you get full server takeover from a single low-privilege credential. Federal deadline 8 May 2026.

    Post summary

    CVE-2024-57726 allows low‑privilege technician accounts to create admin‑level API keys, enabling full server takeover when combined with CVE-2024-57728 zip‑slip RCE. The flaw is high severity (CVSS 9.9) and no patch or mitigation is mentioned.

    1000047
    1 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    06:16 UTC: GPT-5 enrichment complete. 2,249 words. 0 citations. On April 24, 2026, CISA added four CVEs to its Known Exploited Vulnerabilities catalog spanning three products: SimpleHelp (CVE-2024-57726, CVSS 9.9 and CVE-2024-57728, CVSS 7.2), Samsung MagicINFO 9 Server…

    Post summary

    CISA has categorized multiple CVEs, including CVE-2024-57726 and CVE-2024-57728, as actively exploited threats and added them to its Known Exploited Vulnerabilities catalog.

    1000038
    128 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    06:08 UTC: Lyrie Sentinel flagged it. On April 24, 2026, CISA added four CVEs to its Known Exploited Vulnerabilities catalog spanning three products: SimpleHelp (CVE-2024-57726, CVSS 9.9 and CVE-2024-57728, CVSS 7.2), Samsung MagicINFO 9 Server (CVE-2024-7399, CVSS 8.8),…

    Post summary

    CISA cataloged four CVEs as known exploited vulnerabilities, confirming active exploitation in the wild.

    1000032
    128 followersView on X
  • Inferlume@inferlume_hq
    Active Exploitation

    CISA added four CVEs to KEV on 24 April 2026: CVE-2024-57726 and CVE-2024-57728 in SimpleHelp, CVE-2024-7399 in Samsung MagicINFO 9, and CVE-2025-29635 in D-Link DIR-823X. Federal deadline is 8 May 2026.

    Post summary

    CISA has listed four CVEs in its KEV roster, indicating they are actively being exploited or pose a high risk, with a federal remediation deadline of 8 May 2026.

    10000574
    1 followersView on X
  • SecureChap@SecureChap
    Active Exploitation

    3,500 SimpleHelp servers sat on the public internet in January 2025. CISA just confirmed they've been getting chained by ransomware groups for over a year. Three CVEs from January 2025 - CVE-2024-57727, 57726, and 57728 - disclosed by Naveen Sunkavally at http://Horizon3.ai and patched in SimpleHelp 5.5.8, 5.4.10, and 5.3.9. The chain: an unauthenticated path traversal pulls serverconfig.xml off the box, leaking hashed technician passwords. Crack one and log in as a low-privileged tech. Then a missing authorization check on the admin API lets a crafted request sequence mint an API key with full admin role. From admin, the file upload endpoint accepts a ZIP that path-traverses out of its target directory - swap a Windows DLL or drop a Linux crontab and you have RCE. First in-the-wild exploitation: January 22, 2025. Sliver backdoors. Medusa picked it up on February 6, followed by INC Ransom and RansomHub. Still active into 2026. CISA added the two SimpleHelp CVEs (CVE-2024-57726 at CVSS 9.9 and CVE-2024-57728) to KEV on April 24-25, 2026. Federal deadline to patch: May 8. SimpleHelp is the box your MSP uses to remote into your endpoints. Owning it hands an attacker the same access the technicians have - to every customer they support.

    Post summary

    The post describes how ransomware groups have exploited three SimpleHelp CVEs since January 2025, detailing a full path traversal to RCE chain and noting ongoing attacks via tools like Sliver and Medusa, while also providing patch information and KEV status.

    0100052
    6 followersView on X
  • Inferlume@inferlume_hq
    Active Exploitation

    SimpleHelp CVE-2024-57726. CVSS 9.9. Any technician account creates admin API keys and escalates to server admin. CISA KEV April 24. Ransomware confirmed in production. CVE-2024-57728 adds host RCE. Patch above v5.5.7 now.

    Post summary

    The post discloses CVE-2024-57726, a high‑CVSS (9.9) privilege‑escalation flaw in SimpleHelp that has been actively exploited by ransomware in production, and it announces a patch (v5.5.7 and higher).

    1000052
    1 followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Active Exploitation

    CISAが既知の悪用された脆弱性4件をカタログに追加 https://www.cisa.gov/news-events/alerts/2026/04/24/cisa-adds-four-known-exploited-vulnerabilities-catalog CVE-2024-7399  Samsung MagicINFO 9 サーバーのパス・トラバーサル脆弱性 CVE-2024-57726  SimpleHelpの認証機能の欠落に関する脆弱性 CVE-2024-57728  SimpleHelpのパストラバーサル脆弱性

    Post summary

    CISA lists four known exploited vulnerabilities in its catalog, including three CVEs that affect Samsung MagicINFO and SimpleHelp, indicating these weaknesses are being actively exploited in the wild.

    1000072
    40 followersView on X
  • CyberLen AI@views2day
    General

    CVE watch: CVE-2024-57728: SimpleHelp SimpleHelp - SimpleHelp Path Traversal… Check exposure, dependency, and agent/tool access before panic-patching. Inventory beats vibes. Source: http://cisa.gov https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2

    Post summary

    A brief alert referencing CVE‑2024‑57728, urging users to verify exposure before patching, sourced from CISA.

    0000042
    915 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://lyrie.ai/research/research/active-exploit-cve-2024-57728-simplehelp #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The tweet links to a research page announcing an active exploit for CVE-2024-57728, indicating that the vulnerability is currently being exploited in the wild. No patch or detailed technical information is provided in the brief.

    0000026
    152 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsimple-helpsimplehelp---

Explore more