Metasploit Wrap-Up 04/25/2026
2026-04-28T07:23:46Z•4a0a892f29a50fbb509b26110378be47a0d33105a376414716866d6b4641d179
AIMCP-serverRCESMBbulk-exportdirectory-traversalexploit-moduleskyberlegacy-systemsmetasploitopen-sourceproject-glasswingransomwaresql-injectionsupply-chainvmware-esxivulnerability-discoverywindows
What happened
Rapid7 Metasploit roundup and related posts (Apr 2026): Metasploit received transparency and reliability improvements (more detailed check reasoning, legacy SMB version extraction fixes) and several new modules. Notable modules include an auxiliary for Camaleon CMS directory traversal (CVE-2024-46987), an unauthenticated SQL injection credential dump for AVideo (CVE-2026-28501), and an install.php SQLi-to-RCE exploit for openDCIM (CVE-2026-28517). The feed also includes a Rapid7 analysis of Kyber ransomware (dual Windows and VMware ESXi variants with datastore encryption, VM termination, Tor C
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- 4a0a892f29a50fbb509b26110378be47a0d33105a376414716866d6b4641d179
- Enrichment time
- 2026-04-28T07:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.