ctipilot.chSwitzerland · Europe · Public sector

Samsung MagicINFO 9 Server — unauthenticated path traversal / file write (CVSS 9.8, Mirai, KEV deadline 2026-05-08)

cve · CVE-2024-7399

Story timeline

  1. 2026-05-07CTI Daily Brief — 2026-05-07
    active_vulnsFirst coverage. Unauthenticated SYSTEM-level file write exploited to deploy Mirai botnet payloads; public-sector facilities (airports, hospitals) among deployment contexts; CISA KEV deadline 2026-05-08 (overdue).