As of 2026-09-12, CVE-2024-3400 has substantial public exploitation evidence: listed in CISA KEV, listed in ENISA EUVD (exploited), a public exploit module and a published exploit. Most recent observation: 2026-04-03.
Every public observation ESIP has recorded for this CVE, with its source and date. Follow any one to the original evidence.
| Observation | Source | Date | |
|---|---|---|---|
| Listed in CISA KEV | CISA KEV | 2024-04-12 | View → |
| Listed in ENISA EUVD (exploited) | ENISA EUVD (Exploited) | 2024-04-12 | View → |
| Public exploit reference | ExploitDB | 2026-04-03 | View → |
| Public exploit module | Metasploit | 2026-04-03 | View → |
This is one exposure signal: it describes an exposure class, not any one organization's assets. The MITRE ATT&CK techniques mapped to it:
The MITRE CWE weakness types classified for this exposure class:
| Remediation due date | 2024-04-19 |
|---|---|
| Required action | Apply mitigations per vendor instructions as they become available. Otherwise, users with vulnerable versions of affected devices should enable Threat Prevention IDs available from the vendor. See the vendor bulletin for more details and a patch release schedule. |
| Known ransomware campaign use | Yes |
ESIP's current exposure signal for this CVE, its lifecycle state, trend, velocity, and corroboration, is available through the commercial API.
Get the assessment →Public evidence is not the whole picture. Limited or absent observed evidence is not the same as safety.
Related CVEs: those that share an ATT&CK technique or CWE weakness with this one.
Data provided by ESIP / ZenzizenSec — www.exposuresignal.io · as of 2026-09-12