Metasploit Wrap-Up 04/25/2026

2026-04-28T07:23:46Z4a0a892f29a50fbb509b26110378be47a0d33105a376414716866d6b4641d179
AIMCP-serverRCESMBbulk-exportdirectory-traversalexploit-moduleskyberlegacy-systemsmetasploitopen-sourceproject-glasswingransomwaresql-injectionsupply-chainvmware-esxivulnerability-discoverywindows

What happened

Rapid7 Metasploit roundup and related posts (Apr 2026): Metasploit received transparency and reliability improvements (more detailed check reasoning, legacy SMB version extraction fixes) and several new modules. Notable modules include an auxiliary for Camaleon CMS directory traversal (CVE-2024-46987), an unauthenticated SQL injection credential dump for AVideo (CVE-2026-28501), and an install.php SQLi-to-RCE exploit for openDCIM (CVE-2026-28517). The feed also includes a Rapid7 analysis of Kyber ransomware (dual Windows and VMware ESXi variants with datastore encryption, VM termination, Tor C

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
4a0a892f29a50fbb509b26110378be47a0d33105a376414716866d6b4641d179
Enrichment time
2026-04-28T07:23:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.