Metasploit Modules Turn Old CVEs Into Routine Targets

Public exploit modules change the risk from theoretical to repeatable. Once a flaw lands in Metasploit, unpatched systems stop being obscure findings and become low-effort targets for opportunistic attackers. That is the real shift here, not the CVE announcements themselves. Rapid7 added modules for Marvell QConvergeConsole CVE-2025-6793, GestioIP 3.5.7 CVE-2024-48760, and Dolibarr ERP/CRM CVE-2023-30253. The GestioIP issue is an authenticated unsafe upload handler flaw that can be pushed into remote code execution, and the QConvergeConsole module reads arbitrary files from versions 5.5.0.85 and earlier. The new Vim plugin persistence technique widens the story beyond single-product bugs. It gives defenders another reason to watch Unix workstations and developer systems, because persistence can now be hidden in a normal editor plugin path.

Part of the PlainSec briefing for 2026-05-16

Sources