Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Dyson V16 Piston Animal first impressions: The best new Dyson vacuum cleaner is surprisingly under $1,000. Is it worth it?

Best hookup apps of 2026: I swiped until my thumbs hurt

Looking for guilt-free screen time for your kids? This $45 app can help

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » CISA adds four exploited flaws to KEV, sets federal deadline for May 2026
Celebrities

CISA adds four exploited flaws to KEV, sets federal deadline for May 2026

By April 25, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananApril 25, 2026Network security/infrastructure security

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added four vulnerabilities affecting SimpleHelp, Samsung MagicINFO 9 Server, and D-Link DIR-823X series routers to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

The list of vulnerabilities is below –

CVE-2024-57726 (CVSS Score: 9.9) – A missing authentication vulnerability in SimpleHelp could be used by a low-privileged technician to create an API key with excessive privileges and escalate its privileges to the server administrator role. CVE-2024-57728 (CVSS score: 7.2) – SimpleHelp path traversal vulnerability. This allows an administrative user to upload arbitrary files to any location on the file system by uploading a specially crafted zip file (i.e. a zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user. CVE-2024-7399 (CVSS score: 8.8) – A path traversal vulnerability in Samsung MagicINFO 9 Server could allow an attacker to write arbitrary files with system privileges. CVE-2025-29635 (CVSS Score: 7.5) – Command injection vulnerability in the end-of-life D-Link DIR-823X series routers allows an authorized attacker to execute arbitrary commands on a remote device by sending a POST request to /goform/set_prohibiting via the corresponding function.

Both SimpleHelp flaws are marked as “Unknown” for “Known to be used in ransomware campaigns?” Field Effect and Sophos metrics and reports revealed that this issue was being exploited as a precursor to a ransomware attack early last year. One such campaign is believed to be from the DragonForce ransomware operation.

Exploitation of CVE-2024-7399 has previously been associated with malicious activity deploying the Mirai botnet. Regarding CVE-2025-29635, Akamai disclosed earlier this week that it had recorded an attempt to deliver a Mirai botnet variant named “tuxnokill” against D-Link devices.

To mitigate the ongoing threat, Federal Civilian Executive Branch (FCEB) agencies are encouraged to apply a fix or, in the case of CVE-2025-29635, remove the appliance from service by May 8, 2026.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleSteve Ballmer slams founder he supports after pleading guilty to fraud: “I feel fooled and stupid.”
Next Article History of Science: Chernobyl Nuclear Power Plant Meltdown, Bringing World to the Brink of Disaster — April 26, 1986

Related Posts

Amy Adams wears a little black dress on ‘Late Night’

June 10, 2026

Queen Camilla adorns Fiona Claire’s feathers for London outing

June 10, 2026

Taylor Swift’s beauty at the ‘Toy Story 5’ premiere

June 10, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Dyson V16 Piston Animal first impressions: The best new Dyson vacuum cleaner is surprisingly under $1,000. Is it worth it?

Best hookup apps of 2026: I swiped until my thumbs hurt

Looking for guilt-free screen time for your kids? This $45 app can help

Katei, Le Seseraphim, and Illit release “Iconic by Mistake” music video

Trending Posts

Katei, Le Seseraphim, and Illit release “Iconic by Mistake” music video

June 10, 2026

III Points 2026 adds GZA, Bone Thugs-N-Harmony, Flying Lotus, and more

June 10, 2026

Megan Thee Stallion, David Guetta and EJAE share FIFA World Cup song ‘DNA’

June 10, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.