Weekly Metasploit Update: Modules for SMB-to-Meterpreter, Peyara Remote Mouse RCE exploit, and more

2026-07-05T07:23:41Z61f1b1e429dbb80bce48a424e53e2107921be0f67a4b84594418793519955a33
aiaudiobookshelfauthorization-bypasscve-2025-25205dalfoxdeserialization-rceexploitincident-commandlinux-loongarch64liteLLMmetasploitmeterpretermulti-agent-ainext.jspayloadpeyara-remote-mousepolicypsexecrapid7red-teamingsiemsmbsql-injectionunauthenticated-rcevulnerability-management

What happened

Rapid7 blog roundup covering Metasploit framework updates and broader security commentary. Metasploit additions include: a SMB-to-Meterpreter session upgrade module using PsExec (windows/manage/smb_to_meterpreter); an exploit module for Peyara Remote Mouse 1.0.1 unauthenticated RCE; a linux/loongarch64 exec payload; and multiple scanners/auxiliary modules (Audiobookshelf unauthenticated API auth bypass detecting CVE-2025-25205, LiteLLM proxy pre-auth SQL injection scanner, Next.js middleware auth bypass scanner, Dalfox deserialization RCE, and other improvements). Separate posts discuss Rapid7

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
61f1b1e429dbb80bce48a424e53e2107921be0f67a4b84594418793519955a33
Enrichment time
2026-07-05T07:23:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Weekly Metasploit Update: Modules for SMB-to-Meterpreter, Peyara Remote Mouse RCE exploit, and more · Baitaphish