Vulnerabilities & Exploits · Web App Attack

New Exploits Target Tactical RMM and MajorDoMo

Metasploit published modules for a Jinja2 SSTI in Tactical RMM (CVE-2025-69516) enabling authenticated RCE, and for an unauthenticated MajorDoMo command‑injection (CVE-2026-27175). Public exploit modules reduce attacker effort and heighten risk to internet‑exposed or poorly isolated deployments.

1 source · Mar 6

CVE-2025-69516

NVD KEV

CVSS 8.8 HIGH: a Server-Side Template Injection (SSTI) vulnerability in the /reporting/templates/preview/ endpoint of Amidaware… EPSS 2% (80th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-03-07

Every edition of this story: New Exploits Target Tactical RMM and MajorDoMo

More from today