🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.

SimpleHelp Path Traversal Remote Code Execution (CVE-2024-57728) | MSSP Advisory

High🔴 KEV ALERT
DateMay 6, 2026
CVECVE-2024-57728
CVSS Score7.2
Affectedsimplehelp
📋Executive Summary
CISA added CVE-2024-57728 to the Known Exploited Vulnerabilities catalog targeting SimpleHelp remote access software. The path traversal vulnerability allows admin users to upload malicious zip files that can execute arbitrary code on the server.
⚠️Why It Matters for MSSPs
SimpleHelp is commonly deployed in MSSP environments for remote client access, making your infrastructure a direct target for lateral movement attacks. Client environments using SimpleHelp face immediate compromise risk, and failing to warn clients about this actively exploited vulnerability creates retention and contract liability.
Recommended Action
Audit your infrastructure and all client environments for SimpleHelp installations within 24 hours. Apply vendor patches immediately where possible, or isolate and replace SimpleHelp instances that cannot be patched before the weekend.
🔒
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
Get your first advisory free →
🏷️Threat Category
Vulnerability Disclosure

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.