Public exploit modules make disclosed web RCEs usable by a much wider attacker base. The standard response is to watch for the CVEs, but the real shift is that Metasploit now lowers the skill bar and speeds up opportunistic exploitation against unpatched deployments.
Rapid7 added seven new Metasploit modules this week. Four target remote code execution paths in AVideo, openDCIM, ChurchCRM, and unauthenticated Selenium Grid/Selenoid instances, with CVE anchors including CVE-2026-28501, CVE-2026-28517, and CVE-2025-68109. Three more modules add Windows persistence through Telemetry scheduled tasks, PowerShell profiles, and Microsoft BITS jobs.
The forward risk is broader use of these bugs in routine intrusion attempts, not just by advanced operators. Once a working module exists, exposed web apps and Windows hosts become easier to compromise and harder to evict.