Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

CISA adds four exploited flaws to KEV, sets federal deadline for May 2026

Steve Ballmer slams founder he supports after pleading guilty to fraud: “I feel fooled and stupid.”

Palantir reportedly assists IRS with financial crimes investigation

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » CISA adds four exploited flaws to KEV, sets federal deadline for May 2026
Identity

CISA adds four exploited flaws to KEV, sets federal deadline for May 2026

By April 25, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananApril 25, 2026Network security/infrastructure security

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added four vulnerabilities affecting SimpleHelp, Samsung MagicINFO 9 Server, and D-Link DIR-823X series routers to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

The list of vulnerabilities is below –

CVE-2024-57726 (CVSS Score: 9.9) – A missing authentication vulnerability in SimpleHelp could be used by a low-privileged technician to create an API key with excessive privileges and escalate its privileges to the server administrator role. CVE-2024-57728 (CVSS score: 7.2) – SimpleHelp path traversal vulnerability. This allows an administrative user to upload arbitrary files to any location on the file system by uploading a specially crafted zip file (i.e. a zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user. CVE-2024-7399 (CVSS score: 8.8) – A path traversal vulnerability in Samsung MagicINFO 9 Server could allow an attacker to write arbitrary files with system privileges. CVE-2025-29635 (CVSS Score: 7.5) – Command injection vulnerability in the end-of-life D-Link DIR-823X series routers allows an authorized attacker to execute arbitrary commands on a remote device by sending a POST request to /goform/set_prohibiting via the corresponding function.

Both SimpleHelp flaws are marked as “Unknown” for “Known to be used in ransomware campaigns?” Field Effect and Sophos metrics and reports revealed that this issue was being exploited as a precursor to a ransomware attack early last year. One such campaign is believed to be from the DragonForce ransomware operation.

Exploitation of CVE-2024-7399 has previously been associated with malicious activity deploying the Mirai botnet. Regarding CVE-2025-29635, Akamai disclosed earlier this week that it had recorded an attempt to deliver a Mirai botnet variant named “tuxnokill” against D-Link devices.

To mitigate the ongoing threat, Federal Civilian Executive Branch (FCEB) agencies are encouraged to apply a fix or, in the case of CVE-2025-29635, remove the appliance from service by May 8, 2026.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleSteve Ballmer slams founder he supports after pleading guilty to fraud: “I feel fooled and stupid.”

Related Posts

FIRESTARTER backdoor hits federal Cisco Firepower devices, survives security patch

April 24, 2026

NASA employees fall for Chinese phishing scam targeting US defense software

April 24, 2026

Continuous observability as a decision engine

April 24, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

CISA adds four exploited flaws to KEV, sets federal deadline for May 2026

Steve Ballmer slams founder he supports after pleading guilty to fraud: “I feel fooled and stupid.”

Palantir reportedly assists IRS with financial crimes investigation

Two college students raise $5.1 million pre-seed to build AI social network on iMessage

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.