Metasploit Wrap-Up 04/25/2026

2026-04-25T19:23:57Z70c57c831d167612e1e122b44cded9d0a85c90176334b693264e9bbda802f168
ai-vulnerability-discoveryavideobulk-exportcamaleoncheck-methodsdirectory-traversalexploit-moduleskyberlegacy-smbmcp-servermetasploitopendcimproject-glasswingransomwareremote-code-executionsoftware-supply-chainsql-injectionvmware-esxiwindows

What happened

Collection of Rapid7 blog posts (Apr 2026) covering Metasploit updates and new exploit modules, ransomware analysis, and AI/supply-chain security topics. Metasploit wrap-ups describe improved check-method visibility, legacy SMB fixes, and new modules including Camaleon CMS directory traversal (CVE-2024-46987), AVideo unauthenticated SQLi credential dump (CVE-2026-28501), and an openDCIM install.php SQLi→RCE chain (CVE-2026-28517). Additional posts analyze Kyber ransomware (Windows and VMware ESXi variants), introduce an open-source MCP Server and Agent Skill for bulk export/AI workflows, and讨论

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
70c57c831d167612e1e122b44cded9d0a85c90176334b693264e9bbda802f168
Enrichment time
2026-04-25T19:23:57Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.