CISA's list that day
24 April 2026
On CISA added 4 vulnerabilities to its list of exploited vulnerabilities, in Samsung MagicINFO 9 Server, SimpleHelp and D-Link DIR-823X. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2024-57726Missing Authorization | SimpleHelp SimpleHelp | Patch nowRansomware use, listed within a year | 0.67 | ||
| CVE-2024-57728Path Traversal | SimpleHelp SimpleHelp | Patch nowRansomware use, listed within a year | 0.65 | ||
| CVE-2024-7399Path Traversal | Samsung MagicINFO 9 Server | Patch this weekMetasploit module; EPSS 0.92 | 0.92 | ||
| CVE-2025-29635Command Injection | D-Link DIR-823X | Patch this weekEPSS 0.88 | 0.88 |