CISA Flags 4 Actively Exploited Flaws in SimpleHelp, Samsung & D-Link. GCC Enterprises Must Patch by May 8, 2026
CISA has confirmed active exploitation of 4 flaws in SimpleHelp, Samsung MagicINFO and D-Link DIR-823X routers. With a May 8, 2026 federal deadline, GCC enterprises running these products must act now. No patch exists for D-Link.

Network patch panel and vulnerability assessment report in a GCC corporate server room environment
Four Actively Exploited Vulnerabilities Added to CISA's KEV — GCC Enterprises Should Take Note
The U.S. Cybersecurity and Infrastructure Security Agency added four vulnerabilities to its Known Exploited Vulnerabilities catalog on Friday, confirming active exploitation of flaws across three widely deployed products: SimpleHelp, Samsung MagicINFO 9 Server, and D-Link DIR-823X series routers. Federal agencies in the United States have been given until May 8, 2026 to apply fixes or discontinue use of affected devices.
While the KEV catalog is a directive aimed at US federal bodies, the products involved are deployed extensively across enterprise and SME environments in the UAE, Saudi Arabia, and the broader GCC region. For regional security teams, this is not an American compliance issue. It is a live threat affecting infrastructure they likely manage today.
What Was Added and Why It Matters
Understanding the Severity Scores
Each vulnerability is assigned a CVSS score, which stands for Common Vulnerability Scoring System, rated on a scale of 0 to 10. For readers less familiar with the scale, the practical severity bands are:
- 9.0 to 10.0 — Critical: Immediate action required. These flaws are exploitable remotely with little or no user interaction needed and full system compromise is likely
- 7.0 to 8.9 — High: Urgent action required. These flaws carry significant impact on confidentiality, integrity, or availability
- 4.0 to 6.9 — Medium: These should be addressed within standard patch cycles
- Below 4.0 — Low: Monitor and patch as resources allow
All four vulnerabilities in this advisory fall in the High to Critical range, with CVE-2024-57726 in SimpleHelp scoring 9.9 and placing it just below the maximum. For GCC enterprise security teams using risk-based patch prioritization frameworks, all four should be treated as immediate priorities regardless of their position in the queue.
The four vulnerabilities each carry distinct risk profiles for enterprise environments.
CVE-2024-57726 carries a CVSS score of 9.9 and affects SimpleHelp, a remote support and monitoring platform widely used by managed service providers. The flaw is a missing authorization vulnerability that allows a low-privileged technician account to generate API keys with elevated permissions, ultimately enabling full escalation to server admin access. For any organization relying on an MSP that uses SimpleHelp, this represents a significant supply chain risk.
CVE-2024-57728, also in SimpleHelp, scores 7.2 and involves a path traversal vulnerability. An attacker with admin-level access can upload a crafted zip file to write arbitrary files anywhere on the file system, leading to remote code execution under the SimpleHelp server's process context. Research from Field Effect and Sophos had previously linked both SimpleHelp flaws to active ransomware precursor activity, with at least one confirmed connection to the DragonForce ransomware operation.
CVE-2024-7399 scores 8.8 and targets Samsung MagicINFO 9 Server, the content management platform behind Samsung's commercial digital signage ecosystem. The vulnerability allows an unauthenticated attacker to write arbitrary files with system-level authority via path traversal. In the GCC context, this carries particular weight. Samsung MagicINFO is embedded across retail chains, hotel lobbies, airports, and smart building infrastructure throughout the UAE and Saudi Arabia. Past exploitation of this flaw has been linked to Mirai botnet deployment, meaning compromised MagicINFO servers have been conscripted into distributed attack infrastructure.
CVE-2025-29635 scores 7.5 and affects D-Link DIR-823X routers, devices that have reached end-of-life status and will receive no vendor patch. The vulnerability is a command injection flaw exploitable via a POST request to the router's web interface. Akamai disclosed earlier this week that it observed active attempts against D-Link devices deploying a Mirai botnet variant called "tuxnokill." CISA's guidance for this specific CVE is unambiguous: if your organization is still running DIR-823X hardware, discontinue use immediately.
⚠️ ACTION REQUIRED: Hardware Retirement Unlike the other three CVEs in this advisory, there is no patch available for CVE-2025-29635. D-Link DIR-823X routers are end-of-life and the vendor will not release a fix. If your organization has any DIR-823X device operational on its network, regardless of how it is configured or how long it has been running without incident, it must be treated as a live and unmitigated entry point. The only defensible response is immediate hardware replacement. Do not wait for a scheduled refresh cycle.
The End-of-Life Problem Is a GCC Problem Too
The D-Link situation deserves particular attention in a regional context. End-of-life networking hardware remains common across MENA enterprises, particularly in SMEs, hospitality groups, and mid-tier commercial real estate, where hardware refresh cycles are frequently deprioritized in favor of operational continuity. When a vulnerability is actively exploited and no patch exists, the only defensible position is replacement. Continuing to operate EOL devices because they still function is no longer a cost question. It is a liability question.
For organizations assessing their network perimeter exposure, CISA's Known Exploited Vulnerabilities catalog is a practical starting point for prioritizing remediation effort and it is publicly accessible.
Ransomware and Botnet Deployment: The Dual Threat
Two distinct threat actor behaviors are visible across these four CVEs, and both are relevant to enterprise defenders in the region.
The SimpleHelp vulnerabilities have been used as entry points for ransomware staging. This refers not to the final payload delivery but to the initial access and privilege escalation that precedes it. The DragonForce ransomware group, which has previously targeted organizations across multiple sectors, is among those linked to this activity. For security operations teams, this reinforces the importance of monitoring remote access tool usage and flagging anomalous API key generation as a potential indicator of compromise.
The Samsung and D-Link vulnerabilities are being exploited to build botnet capacity. Mirai variants, including the tuxnokill campaign targeting D-Link devices, absorb compromised endpoints into networks used for distributed denial-of-service attacks, credential stuffing operations, and further propagation. An organization that discovers its MagicINFO server or D-Link router was compromised may find itself not only a victim but an unwitting participant in attacks against others.
What GCC Security Teams Should Action This Week
The May 8 federal deadline in the US provides a useful urgency benchmark. For regional enterprises and their security leads, the practical actions are clear and immediate:
- SimpleHelp audit now: Identify all SimpleHelp deployments, both internal and via third-party MSPs. Confirm patches for CVE-2024-57726 and CVE-2024-57728 have been applied. Audit recent API key generation logs for anomalous activity, as unusual keys created by low-privileged accounts are a confirmed indicator of compromise in active DragonForce campaigns
- Samsung MagicINFO 9 patch immediately: Locate all MagicINFO server instances across your environment. Apply the available patch for CVE-2024-7399 without delay. Review server-side logs for unauthorized file write events, particularly any unexpected files appearing outside standard application directories
- D-Link DIR-823X replace and do not patch: There is no fix available and active exploitation is confirmed. Any DIR-823X device still operational in your network is a live entry point. Initiate hardware replacement immediately and treat any device that was running as potentially compromised until forensically cleared
- Strengthen your patch management process: The KEV catalog is updated continuously. GCC enterprise security teams should have a standing process to review new KEV additions weekly rather than reactively after a breach, and map them against internal asset inventories
This week's KEV additions also need to be read in the context of Singapore's CSA advisory on frontier AI, which warned that AI tools are now compressing the window between vulnerability disclosure and active exploitation from months to hours. The practical consequence for patch management teams is stark: the time between a CVE appearing and it being weaponized is shrinking. Delays that were once tolerable are no longer.
For broader guidance on building a GRC framework that keeps pace with evolving threats, MCW's GCC compliance coverage provides the structural context security leadership teams need. For ongoing CVE and threat intelligence specific to GCC enterprise environments, the MENA CyberWire threat intelligence section maintains continuous coverage.
As the UAE and Saudi Arabia both continue expanding their critical infrastructure digitization under Vision 2030 and Smart Dubai frameworks, the exposure surface for these kinds of vulnerabilities only grows. For ongoing coverage of how Saudi Arabia's cybersecurity compliance landscape is evolving alongside Vision 2030, Saudi Future Tech provides regular national-level analysis.
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.