CISA Adds Four Actively Exploited Flaws to KEV, Sets May 2026 Federal Remediation Deadline
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has newly listed four vulnerabilities-impacting SimpleHelp, Samsung MagicINFO 9 Server, and the D-Link DIR-823X router series-on its Known Exploited Vulnerabilities (KEV) catalog after finding evidence they are being abused in the wild.
Details for the vulnerabilities added to the KEV are as follows:
- CVE-2024-57726 (CVSS 9.9) – An authorization control deficiency in SimpleHelp that enables technicians with limited privileges to generate API keys carrying overly broad permissions. Those keys can be leveraged to elevate the attacker’s rights to that of the server administrator.
- CVE-2024-57728 (CVSS 7.2) – A path traversal weakness in SimpleHelp where an administrator account can push a specially crafted ZIP archive (a ZIP slip) to place files anywhere on the host file system. This can be used to run arbitrary code under the SimpleHelp server user.
- CVE-2024-7399 (CVSS 8.8) – A path traversal flaw in Samsung MagicINFO 9 Server that may permit an attacker to write files with system-level privileges.
- CVE-2025-29635 (CVSS 7.5) – A command injection issue affecting end-of-life D-Link DIR-823X routers. An authenticated actor can execute arbitrary commands on the device by issuing a POST request to /goform/set_prohibiting that triggers the vulnerable function.
CISA noted active exploitation as the reason for the KEV additions. Although the SimpleHelp defects are labeled “Unknown” in the KEV column that tracks whether a vulnerability is “Known To Be Used in Ransomware Campaigns,” security vendors Field Effect and Sophos reported last year that attackers leveraged these weaknesses as an initial foothold before deploying ransomware; one such intrusion was linked to the DragonForce ransomware group.
Separately, exploitation of CVE-2024-7399 has previously been associated with activity that distributed the Mirai botnet. And Akamai disclosed this week that it observed attempts targeting D-Link devices to install a Mirai variant identified as “tuxnokill,” tying into the CVE-2025-29635 issue.
To reduce the ongoing risk, CISA is urging Federal Civilian Executive Branch (FCEB) agencies to implement vendor patches. For the out-of-support D-Link DIR-823X appliances affected by CVE-2025-29635, the agency recommends retiring the devices by May 8, 2026 if fixes are not available.
Organizations operating any of the impacted products should verify they have applied the appropriate updates or follow vendor guidance and mitigations to prevent exploitation.