ctipilot.chSwitzerland · Europe · Public sector

SimpleHelp RMM — missing authorisation privilege escalation (CVSS 9.9, ITW DragonForce/Medusa, KEV deadline 2026-05-08)

cve · CVE-2024-57726

Story timeline

  1. 2026-05-07CTI Daily Brief — 2026-05-07
    active_vulnsFirst coverage. Low-privileged user escalates to server admin; chained with CVE-2024-57728 by DragonForce and Medusa ransomware targeting MSPs; CISA KEV deadline 2026-05-08 (overdue).