CISA added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation affecting Samsung MagicINFO 9 Server, SimpleHelp, and D-Link DIR-823X devices. The newly listed flaws are CVE-2024-7399 in Samsung MagicINFO, CVE-2024-57726 and CVE-2024-57728 in SimpleHelp, and CVE-2025-29635 in D-Link DIR-823X. The Samsung issue allows unauthenticated attackers to upload JSP files and execute code with system-level privileges, while the D-Link flaw is a command injection bug that Akamai said is being exploited by a Mirai botnet through crafted POST requests.
The two SimpleHelp vulnerabilities are especially concerning because they can be chained from a low-privileged technician account into full server and downstream host compromise, a pattern linked to ransomware precursor activity. Under Binding Operational Directive 22-01, Federal Civilian Executive Branch agencies must remediate the KEV-listed flaws by May 8, 2026, and CISA urged broader patching and review as attackers increasingly target peripheral infrastructure such as remote support platforms, digital signage servers, and SOHO edge devices.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
Under Binding Operational Directive 22-01, CISA required Federal Civilian Executive Branch agencies to remediate the newly listed KEV vulnerabilities by 2026-05-08. Private organizations were also urged to review and patch affected systems.
CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2024-7399 in Samsung MagicINFO 9 Server, CVE-2024-57726 and CVE-2024-57728 in SimpleHelp, and CVE-2025-29635 in D-Link DIR-823X. The agency cited evidence of active exploitation for all four flaws.
Akamai reported that a Mirai botnet was exploiting CVE-2025-29635 in D-Link DIR-823X routers using crafted POST requests. This established active exploitation of the D-Link vulnerability in the wild.
Researchers observed exploitation of CVE-2024-7399 in Samsung MagicINFO 9 Server shortly after public proof-of-concept code was released. The flaw allows unauthenticated attackers to upload JSP files and execute code with system-level privileges.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.