Malware · 166 giorni fa

Metasploit Adds Public RCE Modules for Web Apps

Public exploit modules make disclosed web RCEs usable by a much wider attacker base. The standard response is to watch for the CVEs, but the real shift is that Metasploit now lowers the skill bar and speeds up opportunistic exploitation against unpatched deployments.

Rapid7 added seven new Metasploit modules this week. Four target remote code execution paths in AVideo, openDCIM, ChurchCRM, and unauthenticated Selenium Grid/Selenoid instances, with CVE anchors including CVE-2026-28501, CVE-2026-28517, and CVE-2025-68109. Three more modules add Windows persistence through Telemetry scheduled tasks, PowerShell profiles, and Microsoft BITS jobs.

The forward risk is broader use of these bugs in routine intrusion attempts, not just by advanced operators. Once a working module exists, exposed web apps and Windows hosts become easier to compromise and harder to evict.

CVE-2026-28517

NVD KEV

CVSS 9.8 CRITICAL: openDCIM version 23.04, through commit 4467e9c4, contains an OS command injection vulnerability in report_network_map.php. EPSS 9% (95º percentile).

CVE-2025-68109

NVD KEV

CVSS 9.1 CRITICAL: churchCRM is an open-source church management system. EPSS 2% (74º percentile).

CVE-2026-28501

NVD KEV

CVSS 9.8 CRITICAL: wWBN AVideo is an open source video platform. EPSS 1% (71º percentile).

Cronologia

Fonti

1 fonte che coprono questa storia

Entità

Riepilogo fornitore: Microsoft

Part of the PlainSec briefing for 2026-04-18

Editions