Record WatchRecord
SimpleHelp broke into the most-exploited products of the last 90 days
23 July 2026 · Timeframe: Trailing 90 days vs the preceding 90
SimpleHelp is now among the top 15 products by CISA-KEV listings over the last 90 days, after not making that list in the preceding 90. A product rising quarter-over-quarter means its exploited footprint is growing right now, not decades ago.
Why it matters
A trailing-90-day view of the most-exploited products is the timely version of this signal: it surfaces what attackers are actively working, not a legacy all-time average dominated by long-since-patched software.
What to do
- CISOs. Check whether SimpleHelp is in your estate and, if so, raise its patch and monitoring priority.
- Lean IT orgs. If you run SimpleHelp, treat its KEV items as front-of-line this cycle.
- MSPs. Flag SimpleHelp across client stacks; a newly-rising exploited product is a proactive-outreach reason.
Our take
A product climbing the recent exploited list is a leading indicator worth acting on before it is your incident. The timely list is the one whose changes matter.
More records like this: Products breaking into the most-exploited list →