Metasploit published modules for a Jinja2 SSTI in Tactical RMM (CVE-2025-69516) enabling authenticated RCE, and for an unauthenticated MajorDoMo command‑injection (CVE-2026-27175). Public exploit modules reduce attacker effort and heighten risk to internet‑exposed or poorly isolated deployments.
Part of the PlainSec briefing for 2026-03-07