April 24, 2026 · Applied Cybernetics Group
CVE-2024-57726 — SimpleHelp SimpleHelp
known ransomware use
SimpleHelp Missing Authorization Vulnerability
- Added to KEV
2026-04-24- Federal due date
2026-05-08- Vendor
- SimpleHelp
- Product
- SimpleHelp
- EPSS
- 97.3th percentile (score 0.388, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2024-57726
CISA short description
SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.