CVE-2024-7399Active Exploitation(samsung / magicinfo_9_server)

HIGHCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch samsung magicinfo_9_server systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.

7.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-05-08. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-22CWE-434

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • magicinfo_9_server

Threat summary

  • Active exploitation appears in 14 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 31 mentions across 13 observed days

What's happening

  • Active exploitation reported across 14 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 10 signals
  • Technical details provided in 22 signals
  • Disclosure: 6 classified signals
  • General: 6 classified signals
  • Peaked 11d ago at 4 mentions (2026-04-24); latest day: 1
  • 31 total mentions across 13 days

Affected systems

Vendors
Products
magicinfo_9_server

Deep dive

Activity timeline31 mentions / 13d
01234Mentions · 2026-03-22: 1Mentions · 2026-04-24: 4Mentions · 2026-04-25: 3Mentions · 2026-04-26: 4Mentions · 2026-04-27: 3Mentions · 2026-04-29: 4Mentions · 2026-04-30: 4Mentions · 2026-05-01: 3Mentions · 2026-05-02: 1Mentions · 2026-05-06: 1Mentions · 2026-05-07: 1Mentions · 2026-05-16: 1Mentions · 2026-06-07: 1PoC Mentioned / Linked · 2026-04-27: 1PoC Mentioned / Linked · 2026-05-07: 1PoC Mentioned / Linked · 2026-05-16: 1Exploit Tool / Code · 2026-04-27: 1Active Exploitation · 2026-03-22: 1Active Exploitation · 2026-04-25: 2Active Exploitation · 2026-04-26: 3Active Exploitation · 2026-04-27: 2Active Exploitation · 2026-04-30: 3Active Exploitation · 2026-05-01: 1Active Exploitation · 2026-05-07: 1Active Exploitation · 2026-05-16: 1Patch / Workaround · 2026-04-24: 1Patch / Workaround · 2026-04-26: 1Patch / Workaround · 2026-04-27: 1Patch / Workaround · 2026-04-29: 1Patch / Workaround · 2026-04-30: 1Patch / Workaround · 2026-05-01: 2Patch / Workaround · 2026-05-02: 1Patch / Workaround · 2026-05-06: 1Patch / Workaround · 2026-05-16: 1Technical Details · 2026-03-22: 1Technical Details · 2026-04-24: 4Technical Details · 2026-04-25: 1Technical Details · 2026-04-26: 1Technical Details · 2026-04-27: 2Technical Details · 2026-04-29: 2Technical Details · 2026-04-30: 4Technical Details · 2026-05-01: 2Technical Details · 2026-05-02: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-16: 1Technical Details · 2026-06-07: 103-2204-2404-2504-2604-2704-2904-3005-0105-0205-0605-0705-1606-07
Signal classification4 categories
Active Exploitation
1445.2%
Disclosure
619.4%
General
619.4%
Patch
516.1%
Referenced assets27 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-221
Active Exploitation1
2026-04-244
Disclosure3Patch1
2026-04-253
Active Exploitation2General1
2026-04-264
Active Exploitation3General1
2026-04-273
Active Exploitation2General1
2026-04-294
Disclosure2General2
2026-04-304
Active Exploitation3Patch1
2026-05-013
Active Exploitation1General1Patch1
2026-05-021
Patch1
2026-05-061
Patch1
2026-05-071
Active Exploitation1
2026-05-161
Active Exploitation1
2026-06-071
Disclosure1
Full discourse20 posts
  • Dark Web Informer@DarkWebInformer
    Active Exploitation

    ‼️🇩🇪 A threat actor claims to have breached Aigner Immobilien, a leading real estate brokerage company based in Munich, Germany with over 30 years of experience. The attacker details the intrusion method: initial access via CVE-2024-7399 into a Windows 11 environment, followed by network mapping via SMB, then pivoting to a backend MSSQL server where they gained ADMINISTRATOR/SYSTEM access and dumped the database. The data is estimated to contain 200,000–300,000 customer records. The threat actor notes the company has since killed access across multiple servers after discovering the breach.

    Post summary

    The post reports that a threat actor actively exploited CVE‑2024‑7399 against Aigner Immobilien, but no PoC, exploit code, patch, or false‑positive information is provided.

    11712288830.0K
    179.5K followersView on X
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ Four vulnerabilities have been added to the CISA KEV Catalog CVE-2025-29635 - D-Link DIR-823X Command Injection Vulnerability CVE-2024-7399 - Samsung MagicINFO 9 Server Path Traversal Vulnerability CVE-2024-57728 - SimpleHelp Path Traversal Vulnerability CVE-2024-57726 - SimpleHelp Missing Authorization Vulnerability https://darkwebinformer.com/cisa-kev-catalog/

    Post summary

    The post announces the addition of four CVEs to the CISA KEV Catalog, providing minimal technical details but no evidence of exploitation or mitigation.

    1602175.6K
    222.6K followersView on X
  • TrendAI Zero Day Initiative@thezdi
    Disclosure

    CVE-2024-7399 Samsung MagicINFO 9 Server getFileFromMultipartFile Directory Traversal Remote Code Execution Vulnerability was disclosed through our program and tracked as ZDI-24-1128 https://www.zerodayinitiative.com/advisories/ZDI-24-1128/

    Post summary

    CVE‑2024‑7399 for Samsung MagicINFO 9 Server has been disclosed as a Directory Traversal Remote Code Execution vulnerability via ZDI, with no PoC, exploit, or patch details provided in the text.

    0101167.5K
    88.7K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(4/24追加) 🛡️No.1581 CVE-2024-7399 Samsung MagicINFO 9 Server Path Traversal Vulnerability ✅概要 ・深刻度:緊急 9.8 (CVSS Base) / NVD ・種別:パス・トラバーサル (CWE-22) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Samsung MagicINFO 9 Server 21.1050未満において、制限されたディレクトリ外へのパス操作により、事前認証されていない攻撃者が任意のファイルをsystem authorityに書き込まれる恐れがある。Arctic Wolfの報告では、細工したJSPファイルのアップロードによりリモートコード実行に至る可能性がある。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅攻撃前提条件 ・Samsung MagicINFO 9 Server 21.1050未満が稼働していること。 ・攻撃者が対象サーバへネットワーク越しに到達可能であること。 ・認証は不要。 ✅悪用時影響 ・任意のファイルを書き込まれる ・system authorityでファイルを書き込まれる ・細工したJSPファイルを配置された場合、リモートコードの実行 ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開済み ・ITW:確認済み。Arctic Wolfは、2025年5月初旬に本脆弱性の実環境での悪用を観測したと報告。 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2024-7399 https://security.samsungtv.com/securityUpdates https://davidxbors.github.io/0xpages/posts/cve-2024-7399/ https://arcticwolf.com/resources/blog/cve-2024-7399/ 🛡️No.1582 CVE-2024-57726 SimpleHelp Missing Authorization Vulnerability ✅概要 ・深刻度:緊急 9.9 (CVSS Base) / NVD ・種別:認証の欠如 (CWE-862) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H SimpleHelp remote support software において、低権限の technician が過剰な権限を持つ API key を作成でき、その API key を用いて server admin 権限昇格される恐れがある。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅攻撃前提条件 ・SimpleHelp の脆弱バージョンが稼働していること。 ・攻撃者が低権限の technician アカウントを有していること。 ・攻撃者が対象サーバへネットワーク越しに到達可能であること。 ✅悪用時影響 ・過剰な権限を持つ API key を作成される可能性がある。 ・server admin 権限へ昇格される可能性がある。 ・管理者化により、低権限 technician が本来アクセスできない接続先 client machine にアクセスされる可能性がある。 ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み。Microsoft は Storm-1175 が CVE-2024-57726 を含む SimpleHelp の脆弱性を悪用していたと報告し、Trend Micro も DragonForce が CVE-2024-57726 を悪用して低権限ユーザーから管理者アクセスを得ていたと報告。 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2024-57726 https://guides.simple-help.com/kb---security-vulnerabilities-01-2025 https://horizon3.ai/attack-research/disclosures/critical-vulnerabilities-in-simplehelp-remote-support-software/ https://www.microsoft.com/en-us/security/blog/2026/04/06/storm-1175-focuses-gaze-on-vulnerable-web-facing-assets-in-high-tempo-medusa-ransomware-operations/ 🛡️No.1583 CVE-2024-57728 SimpleHelp Path Traversal Vulnerability ✅概要 ・深刻度:重要 7.2 (CVSS Base) / NVD (NVD) ・種別:リンク解釈の問題 (CWE-59) (NVD) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H (NVD) SimpleHelp remote support software v5.5.7以前において、管理者ユーザーが細工されたZIPファイルをアップロードすることで、ファイルシステム上の任意の場所へファイルを書き込まれる恐れがある。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅攻撃前提条件 ・SimpleHelp v5.5.7以前の脆弱バージョンが稼働していること。 ・攻撃者が管理者ユーザー、または管理者権限を持つtechnicianとしてログイン可能であること。 ・細工されたZIPファイルをアップロードできること。 ✅悪用時影響 ・ファイルシステム上の任意の場所にファイルを書き込まれる可能性がある。 ・SimpleHelpサーバーユーザー権限で任意コード実行に至る可能性がある。 ・Linuxサーバではcrontabファイルの配置、WindowsサーバではSimpleHelpが使用する実行ファイルやライブラリの上書きにより悪用される可能性がある。 ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み。Trend Microは、DragonForceがSimpleHelpの脆弱性としてCVE-2024-57728をラテラルムーブメントや情報収集に悪用していたと報告。 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2024-57728 https://simple-help.com/kb---security-vulnerabilities-01-2025#security-vulnerabilities-in-simplehelp-5-5-7-and-earlier https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-dragonforce 🛡️No.1584 CVE-2025-29635 D-Link DIR-823X Command Injection Vulnerability ✅概要 ・深刻度:重要 7.2 (CVSS Base) / CISA-ADP (NVD) ・種別:コマンドインジェクション (CWE-77) (NVD) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H (NVD) D-Link DIR-823X ファームウェア 240126 および 240802 には、/goform/set_prohibiting への POST リクエストを通じて任意のコマンドを実行される恐れがある。 対象機器の DIR-823X は、D-Link により EOL/EOS とされており、D-Link は停止と置き換えを推奨。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:高 ✅攻撃前提条件 ・D-Link DIR-823X のファームウェア 240126 または 240802 が稼働していること。 ・攻撃者が対象機器へネットワーク越しに到達可能であること。 ・認証済みの攻撃者であること。 ✅悪用時影響 ・リモートで任意のコマンドを実行される可能性がある。 ・機密性、完全性、可用性に高い影響が生じる可能性がある。 ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み。Akamai SIRT は、2026年3月初旬にグローバルなハニーポット網でこの脆弱性の悪用を確認し、Mirai 亜種の展開に使われていると報告。 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-29635 https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10469 https://www.akamai.com/blog/security-research/cve-2025-29635-mirai-campaign-targets-d-link-devices https://www.cisa.gov/news-events/alerts/2026/04/24/cisa-adds-four-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    This bulletin highlights multiple critical CVEs that are actively exploited in the wild, provides publicly available PoCs and exploit code, and cites vendor advisories with patch or mitigation information.

    000415.0K
    43.6K followersView on X
  • Elusive@ElusivePrivacy
    Active Exploitation

    📋CISA added four actively exploited vulnerabilities to the KEV catalog: 🔸CVE-2024-57726 / CVE-2024-57728 — SimpleHelp (privilege escalation + path traversal, linked to DragonForce ransomware) 🔸CVE-2024-7399 — Samsung MagicINFO 9 Server path traversal (Mirai delivery observed) 🔸CVE-2025-29635 — D-Link DIR-823X command injection (EOL device, no patch retire it) Federal deadline: May 8, 2026. 📄 Source: CISA 👉 Follow @VulnerabilityNw — full catalog coverage on our Telegram → http://t.me/VulnerabilityNews

    Post summary

    The tweet announces that four CVEs have been added to CISA's KEV catalog as actively exploited, highlighting associated threats such as DragonForce ransomware and Mirai activity.

    11020161
    185 followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2024-7399 - high 🚨 Samsung MagicINFO 9 Server 21.1050.0 - Remote Code Execution > Improper limitation of a pathname to a restricted directory vulnerability in Samsung ... 👾 https://cloud.projectdiscovery.io/library/CVE-2024-7399 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces CVE-2024-7399, a high severity Remote Code Execution flaw in Samsung MagicINFO 9 Server, describing the root cause as an improper pathname limitation.

    0001168
    952 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    06:19 UTC: Thread live on @lyrie_ai. On April 24, 2026, CISA added four CVEs to its Known Exploited Vulnerabilities catalog spanning three products: SimpleHelp (CVE-2024-57726, CVSS 9.9 and CVE-2024-57728, CVSS 7.2), Samsung MagicINFO 9 Server (CVE-2024-7399, CVSS 8.8),…

    Post summary

    CISA announced that four CVEs—including two in SimpleHelp and one in Samsung MagicINFO 9 Server—are actively exploited in the wild, as reflected in its Known Exploited Vulnerabilities catalog.

    2000044
    128 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    09:05 UTC: First exploit attempt in the wild. On April 24, 2026, CISA added four CVEs to its Known Exploited Vulnerabilities catalog spanning three products: SimpleHelp (CVE-2024-57726, CVSS 9.9 and CVE-2024-57728, CVSS 7.2), Samsung MagicINFO 9 Server (CVE-2024-7399,…

    Post summary

    The text announces the first reported wild exploitation of several CVEs, with CISA cataloging them as known exploited vulnerabilities, indicating active attacks.

    1001055
    128 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2024-7399 2 - CVE-2023-50224 3 - CVE-2025-48700 4 - CVE-2025-20333 5 - CVE-2026-5281 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The tweet simply lists five CVE identifiers as trending topics, offering no further detail on exploitation, mitigation, or technical specifics.

    00011811
    1.7K followersView on X
  • Inferlume@inferlume_hq
    General

    Priority order for today. cPanel CVE-2026-41940. SimpleHelp CVE-2024-57726 and CVE-2024-57728. Windows Shell CVE-2026-32202. ActiveMQ CVE-2026-34197. Linux Copy Fail CVE-2026-31431. Samsung MagicINFO CVE-2024-7399. D-Link DIR-823X CVE-2025-29635.

    Post summary

    The text simply lists a set of CVE identifiers without any supporting details, claims, or actionable information.

    100001.0K
    1 followersView on X
  • Inferlume@inferlume_hq
    Active Exploitation

    CVE-2024-7399. Samsung MagicINFO 9 Server. Unauthenticated JSP upload to a servlet endpoint. Executes as SYSTEM. Mirai botnet operators have been actively exploiting this since May 2025. Patch to version 21.1050 now.

    Post summary

    CVE-2024-7399 is being actively exploited in the wild by Mirai botnet operators since May 2025, and a patch (version 21.1050) has been released.

    1000039
    1 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    06:08 UTC: Lyrie Sentinel flagged it. On April 24, 2026, CISA added four CVEs to its Known Exploited Vulnerabilities catalog spanning three products: SimpleHelp (CVE-2024-57726, CVSS 9.9 and CVE-2024-57728, CVSS 7.2), Samsung MagicINFO 9 Server (CVE-2024-7399, CVSS 8.8),…

    Post summary

    CISA’s inclusion of four CVEs in its Known Exploited Vulnerabilities catalog confirms these flaws are actively exploited, spanning multiple products and highlighting urgent risk.

    1000032
    128 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Samsung MagicINFO v< 21.1050. CVE-2024-7399 is a critical path traversal vulnerability in Samsung MagicINFO 9 Server that allows unauthenticated attackers to write arbitrary files with SYSTE

    Post summary

    CVE‑2024‑7399 is a critical path traversal flaw in Samsung MagicINFO 9 Server that permits unauthenticated arbitrary file writes; the post provides vulnerability details but no exploit, patch, or active exploitation information.

    1000032
    125 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2024-7399. CVE-2024-7399: Samsung MagicINFO Path Traversal to SYSTEM-Level RCE

    Post summary

    CVE-2024-7399 exposes a path traversal vulnerability in Samsung MagicINFO, enabling system-level remote code execution.

    1000026
    125 followersView on X
  • Inferlume@inferlume_hq
    General

    CISA added four CVEs to KEV on 24 April 2026: CVE-2024-57726 and CVE-2024-57728 in SimpleHelp, CVE-2024-7399 in Samsung MagicINFO 9, and CVE-2025-29635 in D-Link DIR-823X. Federal deadline is 8 May 2026.

    Post summary

    CISA added four CVEs to the KEV list with a federal remediation deadline, but no exploit, patch, or technical details are provided.

    10000574
    1 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2014-6271 2 - CVE-2026-35535 3 - CVE-2024-7399 4 - CVE-2025-29635 5 - CVE-2026-0628 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post enumerates trending CVE identifiers without providing evidence of exploits, patches, or severity details.

    00010768
    1.7K followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Active Exploitation

    CISAが既知の悪用された脆弱性4件をカタログに追加 https://www.cisa.gov/news-events/alerts/2026/04/24/cisa-adds-four-known-exploited-vulnerabilities-catalog CVE-2024-7399  Samsung MagicINFO 9 サーバーのパス・トラバーサル脆弱性 CVE-2024-57726  SimpleHelpの認証機能の欠落に関する脆弱性 CVE-2024-57728  SimpleHelpのパストラバーサル脆弱性

    Post summary

    CISA has added CVE-2024-7399, CVE-2024-57726, and CVE-2024-57728 to its catalog as known, actively exploited vulnerabilities, confirming in‑the‑wild attacks.

    1000072
    40 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    🚨 CVE-2024-7399: Samsung MagicINFO Server RCE actively exploited — PoC public. Hospitals, airports & retail signage worldwide exposed to full network takeover. Confirmed in CISA KEV. Patch immediately. http://lyrie.ai/research #CyberSecurity

    Post summary

    CVE-2024-7399 is a Samsung MagicINFO Server RCE that is actively being exploited worldwide, a public PoC exists, the vulnerability is confirmed by CISA, and an immediate patch is required.

    0000085
    226 followersView on X
  • Zero Day Unit@zero_day_unit
    Active Exploitation

    Lazarus Group no necesitó credenciales. CVE-2024-7399: path traversal sin auth en Samsung MagicINFO 9. Control de toda la señalización corporativa. T1190 → T1021. ZDU-034 → http://qma.mx/samsung-magicinfo-lazarus-group-path-traversal-cve-2024-7399/ #ZDU034 #LazarusGroup #CVE20247399 #ZeroDayUnit #Ciberseguridad

    Post summary

    The post claims Lazarus Group exploited CVE‑2024‑7399, a path‑traversal flaw in Samsung MagicINFO 9, without requiring credentials, and provides a link for details, but it does not mention any patch or exploit code.

    0000049
    152 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    Samsung MagicINFO 9 Server has a known path traversal vulnerability (CVE-2024-7399) with mitigations required by May 2026. Review vendor guidance and apply patches promptly, or consider discontinuing use if no fix is available. #Cybersecurity

    Post summary

    The post warns of a path traversal flaw (CVE-2024-7399) in Samsung MagicINFO 9 Server, urging users to follow vendor guidance and apply patches by May 2026 or discontinue use.

    0000030
    72 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsamsungmagicinfo_9_server---

Explore more