AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0698 93.6 YES
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Jan 9 Reserved by mitre Apr 24 Added to CISA KEV, remediation due 2026-05-08 Apr 24 Published (CNA: mitre)
Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0698 93.6 YES
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Jan 9 Reserved by mitre Apr 24 Added to CISA KEV, remediation due 2026-05-08 Apr 24 Published (CNA: mitre)
SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.
| Date | Event | Detail |
|---|---|---|
| January 9, 2025 | Reserved | Reserved by mitre |
| April 24, 2026 | KEV ADDED | Added to CISA KEV, remediation due 2026-05-08 |
| April 24, 2026 | Published | Published (CNA: mitre) |
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
|---|---|---|---|---|
| n/a | n/a | — | n/a | — |
Authoritative record: CVE-2024-57728 at cve.org
Weaknesses: CWE-22
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2024-57728 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.