Skip to main content
Security

CISA adds four actively exploited vulnerabilities to catalog, sets May deadline

CISA adds four actively exploited vulnerabilities to catalog, sets May deadline Image: Primary
The U.S. Cybersecurity and Infrastructure Security Agency on Friday added four vulnerabilities to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation. Federal Civilian Executive Branch agencies are recommended to apply fixes or discontinue affected products by May 8, 2026. The flaws include CVE-2024-57726 and CVE-2024-57728 in SimpleHelp remote support software, CVE-2024-7399 in Samsung MagicINFO 9 Server, and CVE-2025-29635 in end-of-life D-Link DIR-823X series routers. CVE-2024-57726 allows low-privileged technicians to create API keys with excessive permissions, which can then be used to escalate privileges to the server admin role. CVE-2024-57728 permits admin users to upload arbitrary files via a crafted zip file, which can be exploited to execute arbitrary code. Both issues have been exploited as precursors to ransomware attacks, with at least one campaign attributed to the DragonForce ransomware operation. CVE-2024-7399 is a path traversal vulnerability in Samsung MagicINFO 9 Server that could allow an attacker to write arbitrary files with system authority. Past exploitation of this flaw has been linked to Mirai botnet activity. CVE-2025-29635 is a command injection vulnerability in D-Link DIR-823X routers that allows an authorized attacker to execute arbitrary commands. Akamai disclosed earlier this week that it recorded attempts against D-Link devices to deliver a Mirai botnet variant named tuxnokill.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security Products
Security Products

Liquid sidechain pauses after reported 4,000 BTC withdrawal

Liquid says purported white-hat hackers withdrew about 4,000 BTC, valued in its statement at roughly $320 million, from the Liquid Federation wallet. The company says the funds left through the SideSwap Peg-out Authorization Key, ...

Security Policy
Security Policy

Berlin reviews ransomware data release after rejecting ransom

Berlin's state government said it is reviewing a 5.79TB trove of stolen data published by the Rhysida ransomware group after the state refused to pay a ransom. Reuters reported that the released files reportedly include national-d...

Security Infrastructure
Security Infrastructure

JetBrains tells Cadence users to rotate credentials after TeamCity breach

JetBrains is telling Cadence users to revoke or rotate credentials and secrets after attackers exploited a critical TeamCity vulnerability to breach a Cadence environment. The company said the attackers accessed a 2024 server back...

Security
Security

PaperCut flaws exploited in credential-theft attacks on schools

Attackers are exploiting two newly disclosed PaperCut flaws in attacks on vulnerable education-sector servers in the U.S. and Europe, according to Arctic Wolf. The security firm described the flaws as an authentication-bypass and ...