CVE-2025-69516
CVSS 8.8 HIGH: a Server-Side Template Injection (SSTI) vulnerability in the /reporting/templates/preview/ endpoint of Amidaware… EPSS 2% (80th percentile).
Vulnerabilities & Exploits · Web App Attack
Metasploit published modules for a Jinja2 SSTI in Tactical RMM (CVE-2025-69516) enabling authenticated RCE, and for an unauthenticated MajorDoMo command‑injection (CVE-2026-27175). Public exploit modules reduce attacker effort and heighten risk to internet‑exposed or poorly isolated deployments.
1 source · Mar 6
CVSS 8.8 HIGH: a Server-Side Template Injection (SSTI) vulnerability in the /reporting/templates/preview/ endpoint of Amidaware… EPSS 2% (80th percentile).
Rapid7
Metasploit Wrap-Up 03/06/2026
Explore the latest Metasploit Framework release focusing on enhanced payloads, new encoder options, and fresh RCE exploits, including Tactical RMM SSTI and MajorDoMo command injection.
originalPart of the PlainSec briefing for 2026-03-07
Every edition of this story: New Exploits Target Tactical RMM and MajorDoMo