Metasploit Wrap-Up 04/17/2026

2026-04-18T19:23:47Z0f848e2b3db9e567d1921c453f7f10a05944617541a4b6fa0444b359a4989c9e
avideobitschurchcrmclickfixcve-2026-33032exploit-modulesmetasploitmicrosoftnginx-uiopenDCIMpatch-tuesdayphishingpost-exploitationpowershell-profilesrapid7rceselenium-gridsql-injectiontelemetrythreat-intelwindows-persistence

What happened

Rapid7 roundup: Metasploit added seven new modules (including unauthenticated SQLi and RCE exploits targeting AVideo and openDCIM, plus RCE modules for Selenium Grid/Selenoid and ChurchCRM) and new Windows post‑exploitation persistence modules (Telemetry scheduled tasks, PowerShell profiles, BITS). Rapid7 also highlights a critical missing‑authentication vulnerability in Nginx UI (CVE-2026-33032, CVSS 9.8), an April 2026 Microsoft Patch Tuesday releasing 167 fixes (with at least one vuln observed exploited in the wild), and an active ClickFix phishing campaign impersonating a Claude installer.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
0f848e2b3db9e567d1921c453f7f10a05944617541a4b6fa0444b359a4989c9e
Enrichment time
2026-04-18T19:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.