SimpleHelp RMM — missing authorisation privilege escalation (CVSS 9.9, ITW DragonForce/Medusa, KEV deadline 2026-05-08)
cve · CVE-2024-57726
Coverage timeline
2
first 2026-05-07 → last 2026-05-10
Briefs
2
2 distinct
Sources cited
10
7 hosts
Sections touched
2
active_vulns, weekly_summary
Co-occurring entities
0
no co-occurrence
Story timeline
- 2026-05-10CTI Weekly Summary — 2026-W19 (May 04 – May 10, 2026)
- 2026-05-07CTI Daily Brief — 2026-05-07
Where this entity is cited
- active_vulns1
- weekly_summary1
Source distribution
- nvd.nist.gov3 (30%)
- horizon3.ai2 (20%)
- cloud.google.com1 (10%)
- helpnetsecurity.com1 (10%)
- securityboulevard.com1 (10%)
- simple-help.com1 (10%)
- windowsforum.com1 (10%)
External references
All cited sources (10)
- nvd.nist.govprimaryinlineNVD CVE-2024-57726https://nvd.nist.gov/vuln/detail/CVE-2024-57726
- nvd.nist.govprimaryinlineNVD CVE-2024-57728https://nvd.nist.gov/vuln/detail/CVE-2024-57728
- nvd.nist.govprimaryinlineNVD CVE-2024-7399https://nvd.nist.gov/vuln/detail/CVE-2024-7399
- cloud.google.cominlineMandiant/GTIGhttps://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit/
- helpnetsecurity.cominlineHelp Net Security, 2025-05-06https://www.helpnetsecurity.com/2025/05/06/exploited-vulnerability-software-managing-samsung-digital-displays-cve-2024-7399/
- horizon3.aiinlineHorizon3https://horizon3.ai/attack-research/disclosures/cve-2026-48558-simplehelp-authentication-bypass-iocs/
- horizon3.aiinlineHorizon3.ai — SimpleHelp RMM disclosureshttps://www.horizon3.ai/attack-research/disclosures/critical-vulnerabilities-in-simplehelp-remote-support-software/
- securityboulevard.cominlineSecurity Boulevard, 2026-04-24https://securityboulevard.com/2026/04/cisa-warns-of-multiple-simplehelp-vulnerabilities-exploited-in-attacks/
- simple-help.cominlineSimpleHelp, 2026-06-12https://simple-help.com/security/simplehelp-security-update-2026-05
- windowsforum.cominlineWindowsForum, 2026-04-24https://windowsforum.com/threads/cisa-adds-4-kev-flaws-patch-samsung-magicinfo-simplehelp-d-link-dragonforce-ransomware-april-2026/
Items in briefs about SimpleHelp RMM — missing authorisation privilege escalation (CVSS 9.9, ITW DragonForce/Medusa, KEV deadline 2026-05-08)
No parsed item heading or body matches this entity yet. Items match by exact CVE id (for CVE entities), by lead-segment substring of the title in the item heading or body, or by a distinctive anchor token from the title appearing in the item heading. Coverage that lives inside a broader section (no per-item heading) is captured by the Story timeline above.