CISA Alerts on Critical Flaws in SimpleHelp, Samsung MagicINFO, and D-Link Devices
ID: 80b0219a-a927-58fa-b656-6c0587a7b3ab
STIX ID: report--80b0219a-a927-58fa-b656-6c0587a7b3ab
Feed Name: ThreatCluster
Threat Score
*CISA added four actively exploited critical vulnerabilities to its KEV catalog on April 24, 2026 — notably CVE-2024-57726 (CVSS 9.9) in SimpleHelp being exploited by DragonForce ransomware to escalate privileges and deploy ransomware across managed devices, plus a command injection in Samsung MagicINFO 9 and a buffer overflow in D-Link DIR-823X — and ordered federal agencies to remediate by May 8, 2026.*
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
