CVE-2026-28517
CVSS 9.8 CRITICAL: openDCIM version 23.04, through commit 4467e9c4, contains an OS command injection vulnerability in report_network_map.php. EPSS 9% (95º percentile).
Malware e strumenti · Attacco ad app web
Public exploit modules make disclosed web RCEs usable by a much wider attacker base. The standard response is to watch for the CVEs, but the real shift is that Metasploit now lowers the skill bar and speeds up opportunistic exploitation against unpatched deployments.
Rapid7 added seven new Metasploit modules this week. Four target remote code execution paths in AVideo, openDCIM, ChurchCRM, and unauthenticated Selenium Grid/Selenoid instances, with CVE anchors including CVE-2026-28501, CVE-2026-28517, and CVE-2025-68109. Three more modules add Windows persistence through Telemetry scheduled tasks, PowerShell profiles, and Microsoft BITS jobs.
The forward risk is broader use of these bugs in routine intrusion attempts, not just by advanced operators. Once a working module exists, exposed web apps and Windows hosts become easier to compromise and harder to evict.
1 fonte · 17 apr
CVSS 9.8 CRITICAL: openDCIM version 23.04, through commit 4467e9c4, contains an OS command injection vulnerability in report_network_map.php. EPSS 9% (95º percentile).
CVSS 9.1 CRITICAL: churchCRM is an open-source church management system. EPSS 2% (74º percentile).
CVSS 9.8 CRITICAL: wWBN AVideo is an open source video platform. EPSS 1% (71º percentile).
Rapid7
Metasploit Wrap-Up 04/17/2026
These RCE modules target critical vulnerabilities in AVideo (unauthenticated SQLi for credential dumping), openDCIM (chained SQLi to RCE), ChurchCRM (file upload RCE), and a unified module for unauthenticated Selenium Grid/Selenoid instances.
originaleRiepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-04-18
Every edition of this story: Metasploit Adds Public RCE Modules for Web Apps