logo

CISA Warns of Multiple SimpleHelp Vulnerabilities Exploited in Attack

ID: b2b10689-257e-5816-a802-e2386e175f6e

STIX ID: report--b2b10689-257e-5816-a802-e2386e175f6e

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-04-25

Date Updated: 2026-04-25

Author: Abinaya

...
...

**CISA alert: two critical SimpleHelp vulnerabilities (CVE-2024-57726 and CVE-2024-57728) are actively exploited; one allows privilege escalation via missing authorization and the other enables path traversal/zip-slip uploads leading to arbitrary code execution. CISA added them to the KEV catalog and set a remediation deadline of May 8, 2026; organizations should apply vendor updates, monitor for suspicious API key creation and file uploads, and disconnect or discontinue use if mitigations are unavailable.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.