www.cisa.gov 4/24/2026, 5:59:08 PM · via preferred

CISA warns of active SimpleHelp ZIP traversal flaw CVE-2024-57728

CyberSIXT Evidence Panel
Primary Source nvd.nist.gov
CISA KEV Listed in KEV
Patch Patch Available

ACCORDING to CISA, CVE-2024-57728 is listed in the Known Exploited Vulnerabilities Catalog for SimpleHelp, described as a Path Traversal Vulnerability. SimpleHelp allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (zip slip), which can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user. The entry notes a related CWE of 22 and that it is currently Unknown whether it has been used in ransomware campaigns.

Action recommended includes applying mitigations per vendor instructions, following applicable guidance for cloud services, or discontinuing use of the product if mitigations are unavailable. The record shows Date Added as 24 April 2026 and Due Date as 08 May 2026.

View Primary Source Via www.cisa.gov

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline