CVE-2024-7399: Samsung MagicINFO 9 Server Path Traversal Vulnerability

Added to the CISA Known Exploited Vulnerabilities catalog on 24 Apr 2026. Vendor: Samsung. Product: MagicINFO 9 Server.

Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority.

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. (due 08 May 2026)