Critical Vulnerabilities in SimpleHelp Software Exploited
Article Content
- •CVE-2024-57728 allows arbitrary file uploads, risking code execution.
- •CVE-2024-57726 permits privilege escalation via excessive API key permissions.
- •Both vulnerabilities are actively exploited as of April 24, 2026.
Two critical vulnerabilities have been identified in SimpleHelp remote support software versions 5.5.7 and earlier. CVE-2024-57728 allows admin users to upload arbitrary files, potentially executing arbitrary code on the host system. CVE-2024-57726 enables low-privilege technicians to create API keys with excessive permissions, facilitating privilege escalation to server admin roles. Both vulnerabilities were published on January 15, 2025, and were added to the CISA Known Exploited Vulnerabilities Catalog on April 24, 2026, indicating active exploitation. Organizations using affected versions are at risk of unauthorized access and control. Immediate action is recommended to mitigate these vulnerabilities. Reference CISA's BOD 22-01 for further guidance.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2024-57726 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
SonicWall Patches Critical SSRF Vulnerability in SMA1000 Appliances On October 6, 2026, SonicWall released hotfixes for four vulnerabilities in its SMA1000 series appliances, including CVE-2026-102255, a critical server-side request forgery (SSRF) flaw rated 10.0 on the CVSS scale. This vulnerability allows unauthenticated attackers to exploit an unintended access path in the…
Zip Slip Vulnerability Exploitation via Zip File Uploads A utility script has been released to exploit the Zip Slip vulnerability, which allows attackers to extract files to unintended directories via zip file uploads. This vulnerability can lead to remote code execution by placing malicious web shells in accessible directories. The script generates zip files containing…