Metasploit Wrap-Up 04/25/2026
2026-04-25T19:23:57Z•70c57c831d167612e1e122b44cded9d0a85c90176334b693264e9bbda802f168
ai-vulnerability-discoveryavideobulk-exportcamaleoncheck-methodsdirectory-traversalexploit-moduleskyberlegacy-smbmcp-servermetasploitopendcimproject-glasswingransomwareremote-code-executionsoftware-supply-chainsql-injectionvmware-esxiwindows
What happened
Collection of Rapid7 blog posts (Apr 2026) covering Metasploit updates and new exploit modules, ransomware analysis, and AI/supply-chain security topics. Metasploit wrap-ups describe improved check-method visibility, legacy SMB fixes, and new modules including Camaleon CMS directory traversal (CVE-2024-46987), AVideo unauthenticated SQLi credential dump (CVE-2026-28501), and an openDCIM install.php SQLi→RCE chain (CVE-2026-28517). Additional posts analyze Kyber ransomware (Windows and VMware ESXi variants), introduce an open-source MCP Server and Agent Skill for bulk export/AI workflows, and讨论
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- 70c57c831d167612e1e122b44cded9d0a85c90176334b693264e9bbda802f168
- Enrichment time
- 2026-04-25T19:23:57Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.