A path traversal vulnerability, identified as CVE-2024-58387, in Inspur Haiyue HCM Cloud was reportedly exploited on the same day it was publicly disclosed. The vulnerability was reserved and published on September 30, 2026, and its first listing in an exploited vulnerabilities catalog also occurred on that date.
The claim of exploitation on the day of disclosure is primarily supported by its inclusion in the VulnCheck KEV commercial research catalog. The CIRCL aggregator, which mirrors VulnCheck's listings, also reported it on September 30, 2026. However, the vulnerability is not listed in the CISA KEV (US federal) or EUVD (ENISA, European Union) catalogs of exploited vulnerabilities.
The exploitability of CVE-2024-58387 is based on a single catalog entry, with no independent corroboration from a second major catalog. Public exploitation evidence was reported on September 30, 2026, with the information collected from VulnCheck and CIRCL.
The vulnerability has an EPSS (Exploit Prediction Scoring System) score of 0.71%, placing it in the 51.8th percentile, indicating a relatively low probability of exploitation compared to other vulnerabilities. The CVSS severity score for this vulnerability is currently listed as "none."






