High 7.5
KEV + Ransomware
CVE-2024-57727
Exploitation of SimpleHelp CVE-2024-57727
Vendor / product: SimpleHelp
Event date: 2025-06-12
Victim organization: Multiple (utility billing software provider, MSPs, unpatched SimpleHelp customers)
Public PoC: Yes
First tracked by RiskWire: 2026-08-26
CISA KEV catalog
Added to KEV
Federal remediation due
2025-03-06 (563 days overdue)
Ransomware campaign use
Known
CISA description
SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files may include server configuration files and hashed user passwords.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Named threat actors
Ransomware actors (including DragonForce)
Sources & citations (46)
- Hackers target Microsoft SharePoint RCE chain with PoC exploit bleepingcomputer.com · 2026-08-26
- Microsoft SharePoint Flaws Let Unauthenticated Attackers Execute Remote Code gbhackers.com · 2026-08-26
- RMM Phishing Campaign Spans 46 Countries as Attackers Abuse Trusted IT Tools esecurityplanet.com · 2026-08-28
- Klever Fixes 2 Critical KLV Minting Flaws blog.gridinsoft.com · 2026-08-28
- CLOP Is Mass-Exploiting PTC Windchill at Scale. Every AI Agent Connected to It Inherits the Breach. tech.yahoo.com · 2026-08-30
- Critical Ruby on Rails Vulnerability in Attackers' Crosshairs securityweek.com · 2026-08-31
- Attackers exploit critical Rails flaw as patch leaves RCE gap open betanews.com · 2026-08-31
- Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity thehackernews.com · 2026-09-01
- PaperCut Exploitation Escalates to Active Intrusions securityweek.com · 2026-09-01
- PaperCut issues emergency patches as threat actors target chained vulnerabilities cybersecuritydive.com · 2026-08-31
- Metasploit Adds Exploit for PaperCut MF/NG Zero-Day RCE Vulnerabilities gbhackers.com · 2026-08-31
- CISA Warns of Multiple PaperCut NG/MF Vulnerabilities Actively Exploited in Attacks cybersecuritynews.com · 2026-08-31
- U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog securityaffairs.com · 2026-09-01
- Security Leaders Weigh in on Recent PaperCut Vulnerabilities securitymagazine.com · 2026-08-31
- Attackers plant remote access tools on compromised PaperCut servers helpnetsecurity.com · 2026-08-31
- PoC Released for Microsoft Exchange CVE-2026-62911 Pre-Auth RCE Attack Chain ground.news · 2026-09-01
- CVE-2026-81578 Archives securityaffairs.com · 2026-09-01
- Security Check-in Quick Hits: McKesson Extortion Breach, PaperCut Zero-Day Chain Under Active Attack, and JFrog Artifactory Admin Bypass rodtrent.substack.com · 2026-09-01
- Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials thehackernews.com · 2026-09-02
- SonicWall warns of actively exploited SMA1000 zero-day flaws bleepingcomputer.com · 2026-09-02
+26 more sources
References
See CVE-2024-57727 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →