Weekly Metasploit Update: Modules for SMB-to-Meterpreter, Peyara Remote Mouse RCE exploit, and more
2026-07-04T07:23:42Z•5d6cb197119135b07b80e1725eda91a7000931c81dc7962526b8479f19ad1a2f
AIAudiobookshelfCVE-2025-25205LiteLLMNext.jsPeyara Remote MousePsExecSMBSQL injectiondeserialization RCEexploitmetasploitmeterpreterpost-exploitationred teamstandardsunauthenticated RCEvulnerability management
What happened
Rapid7 published multiple Metasploit Framework updates adding new exploit and post-exploit modules: an unauthenticated RCE module for Peyara Remote Mouse 1.0.1, a post module to upgrade SMB sessions to Meterpreter via PsExec, and a loongarch64 Linux exec payload. Other weekly additions include scanners and modules for Audiobookshelf (unauthenticated API auth bypass), Next.js middleware auth bypass, LiteLLM proxy SQLi, and a Dalfox deserialization RCE. The blog series also discusses Red Team adoption of multi‑agent AI for offensive operations and policy/standards concerns as AI accelerates vuln
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- 5d6cb197119135b07b80e1725eda91a7000931c81dc7962526b8479f19ad1a2f
- Enrichment time
- 2026-07-04T07:23:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.