CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal Deadline
ID: 79d01831-04d7-50c3-ab2f-c10143c98199
STIX ID: report--79d01831-04d7-50c3-ab2f-c10143c98199
Feed Name: The Hacker News
CISA added four actively exploited vulnerabilities to its KEV catalog—CVE-2024-57726 and CVE-2024-57728 in SimpleHelp (privilege escalation and zip-slip), CVE-2024-7399 in Samsung MagicINFO 9 (path traversal), and CVE-2025-29635 in D-Link DIR-823X (command injection). The SimpleHelp flaws have been observed as precursors to ransomware (including a DragonForce-linked campaign), and the Samsung and D-Link issues have been tied to Mirai botnet activity; affected Federal agencies are advised to apply fixes or discontinue affected devices by May 8, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
