What is CVE-2024-57726?
SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.
Timeline
- 2025-01-15Published to the U.S. National Vulnerability Database (NVD)
- 2026-04-24Added to the CISA Known Exploited Vulnerabilities (KEV) catalog
- 2026-05-08CISA federal remediation deadline (BOD 22-01)
- 2026-06-17NVD record last updated
CISA Known Exploited Vulnerability
SimpleHelp Missing Authorization Vulnerability
Affected product
Simple-Help Simplehelp
Remediation Steps
- Access router administration panel and check current firmware version
- Download latest firmware from D-Link support portal for DIR-823X model
- Perform factory backup before firmware update
- Install firmware update via administration interface
- Verify router functionality and change default administrative credentials
References
- https://www.horizon3.ai/attack-research/disclosures/critical-vulnerabilities-in-simplehelp-remote-support-software/
- https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-dragonforce
- https://simple-help.com/kb---security-vulnerabilities-01-2025#security-vulnerabilities-in-simplehelp-5-5-7-and-earlier
- https://www.cisa.gov/news-events/alerts
- https://support.dlink.com
- https://nvd.nist.gov/vuln/detail/CVE-2024-57726
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 4 of April 2026 (April 27 – May 3)
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.