Weekly Metasploit Update: Modules for Audiobookshelf, LiteLLM, Next.js, Dalfox and more

2026-06-28T07:23:46Zdae61722b06d39338fb168e59bf45c66ee97279cf49faa37199bc6e49049f4be
ai-and-complianceaudiobookshelfauthentication-bypassdalfoxdll-side-loadingdonut-shellcodeexploitin-memory-ratlitellmloader-chainmetasploitnext.jsniss2ntlm-relaypaperclipprivilege-escalationsiemsql-injectionthreat-intelunauthenticated-rce

What happened

Rapid7 blog roundup: multiple Weekly Metasploit updates added new detection and exploit modules — notable inclusions are an Audiobookshelf unauthenticated API authentication bypass (CVE-2025-25205), a Paperclip unauthenticated remote code execution chain (CVE-2026-41679), a LiteLLM proxy pre-auth SQL injection scanner, a Next.js middleware authorization-bypass scanner, a Dalfox deserialization RCE, NTLM relay local privilege escalation tooling, and other exploit/enhancement modules. The site also published a detailed threat analysis of the Dropping Elephant campaign (in-memory RAT, DLL side‑lο

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
dae61722b06d39338fb168e59bf45c66ee97279cf49faa37199bc6e49049f4be
Enrichment time
2026-06-28T07:23:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Weekly Metasploit Update: Modules for Audiobookshelf, LiteLLM, Next.js, Dalfox and more · Baitaphish