CVE-2025-69516
CVSS 8.8 HIGH: a Server-Side Template Injection (SSTI) vulnerability in the /reporting/templates/preview/ endpoint of Amidaware… EPSS 2% (80th percentile).
Vulnerabilities · 193 days ago
Metasploit published modules for a Jinja2 SSTI in Tactical RMM (CVE-2025-69516) enabling authenticated RCE, and for an unauthenticated MajorDoMo command‑injection (CVE-2026-27175). Public exploit modules reduce attacker effort and heighten risk to internet‑exposed or poorly isolated deployments.
CVSS 8.8 HIGH: a Server-Side Template Injection (SSTI) vulnerability in the /reporting/templates/preview/ endpoint of Amidaware… EPSS 2% (80th percentile).
1 source covering this story
Explore the latest Metasploit Framework release focusing on enhanced payloads, new encoder options, and fresh RCE exploits, including Tactical RMM SSTI and MajorDoMo command injection.
Part of the PlainSec briefing for 2026-03-07