Metasploit Wrap-Up 04/17/2026
2026-04-18T19:23:47Z•0f848e2b3db9e567d1921c453f7f10a05944617541a4b6fa0444b359a4989c9e
avideobitschurchcrmclickfixcve-2026-33032exploit-modulesmetasploitmicrosoftnginx-uiopenDCIMpatch-tuesdayphishingpost-exploitationpowershell-profilesrapid7rceselenium-gridsql-injectiontelemetrythreat-intelwindows-persistence
What happened
Rapid7 roundup: Metasploit added seven new modules (including unauthenticated SQLi and RCE exploits targeting AVideo and openDCIM, plus RCE modules for Selenium Grid/Selenoid and ChurchCRM) and new Windows post‑exploitation persistence modules (Telemetry scheduled tasks, PowerShell profiles, BITS). Rapid7 also highlights a critical missing‑authentication vulnerability in Nginx UI (CVE-2026-33032, CVSS 9.8), an April 2026 Microsoft Patch Tuesday releasing 167 fixes (with at least one vuln observed exploited in the wild), and an active ClickFix phishing campaign impersonating a Claude installer.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- 0f848e2b3db9e567d1921c453f7f10a05944617541a4b6fa0444b359a4989c9e
- Enrichment time
- 2026-04-18T19:23:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.