LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-57728: SimpleHelp Path Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 24, 2026
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 8, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-57728 to its Known Exploited Vulnerabilities catalog on Apr 24, 2026, with a federal patch deadline of May 8, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited…

SimpleHelp contains a path traversal vulnerability that lets an administrator upload a specially crafted zip file and write arbitrary files to any location on the server file system. The flaw can be used to place executable code that then runs with the privileges of the SimpleHelp server process. Because the issue is already known to be used by ransomware operators, any internet-facing or remotely accessible SimpleHelp instance should be treated as high priority for review.

How it works

The weakness is classified as CWE-22, improper limitation of a pathname to a restricted directory. An authenticated administrator uploads a zip archive whose entries contain path traversal sequences. When the archive is extracted, files are written outside the intended directory, allowing placement of code in locations the server process can later execute.

Am I affected? How to find it in your systems

Inventory every deployment of SimpleHelp, including on-premises servers and any instances running in cloud environments. Confirm the exact version and configuration against the vendor advisory, because only the vendor can state which builds contain the flaw. Review administrative accounts and any logs or telemetry that record zip-file uploads or file-extraction events. Look for unexpected files appearing outside normal application directories or changes to startup scripts and service binaries.

How to remediate

Apply the vendor-supplied update referenced in the official advisory. After patching, review administrative access controls and limit the number of users who can perform file-upload operations. Follow any additional hardening steps listed by the vendor for this class of path-traversal issue.

If you can't patch immediately

If your data may have been exposed

Because this vulnerability is known to be used in ransomware campaigns, assume that successful exploitation could lead to data theft or encryption. Run a free exposure scan of your organization’s email domains against known breach data to determine whether credentials or other information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSimpleHelp · SimpleHelp
WeaknessCWE-22
Added to CISA KEVApr 24, 2026
Federal patch deadlineMay 8, 2026
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities