Malware & Tooling · Web App Attack

Metasploit Adds Public RCE Modules for Web Apps

Public exploit modules make disclosed web RCEs usable by a much wider attacker base. The standard response is to watch for the CVEs, but the real shift is that Metasploit now lowers the skill bar and speeds up opportunistic exploitation against unpatched deployments.

Rapid7 added seven new Metasploit modules this week. Four target remote code execution paths in AVideo, openDCIM, ChurchCRM, and unauthenticated Selenium Grid/Selenoid instances, with CVE anchors including CVE-2026-28501, CVE-2026-28517, and CVE-2025-68109. Three more modules add Windows persistence through Telemetry scheduled tasks, PowerShell profiles, and Microsoft BITS jobs.

The forward risk is broader use of these bugs in routine intrusion attempts, not just by advanced operators. Once a working module exists, exposed web apps and Windows hosts become easier to compromise and harder to evict.

1 source · Apr 17

CVE-2026-28517

NVD KEV

CVSS 9.8 CRITICAL: openDCIM version 23.04, through commit 4467e9c4, contains an OS command injection vulnerability in report_network_map.php. EPSS 6% (92nd percentile).

CVE-2025-68109

NVD KEV

CVSS 9.1 CRITICAL: churchCRM is an open-source church management system. EPSS 2% (74th percentile).

CVE-2026-28501

NVD KEV

CVSS 9.8 CRITICAL: wWBN AVideo is an open source video platform. EPSS 2% (71st percentile).

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-04-18

Every edition of this story: Metasploit Adds Public RCE Modules for Web Apps