Metasploit Wrap-Up 04/17/2026
2026-04-20T07:23:44Z•e201d5f53bc42e3f17748339c90d686c1ce0b73f86111e162d4d1b10bfe425e9
avideochurchcrmclickfixexploit-modulesmetasploitnginx-uiopendcimpatch-tuesdaypersistencephishingrceselenium-gridsql-injectionvulnerability-managementwindows-persistence
What happened
Collection of Rapid7 blog posts (April 2026) covering multiple security topics: Metasploit Framework additions (seven new modules including unauthenticated SQLi credential dump for AVideo - CVE-2026-28501, an openDCIM install.php SQLi→RCE exploit - CVE-2026-28517, RCE modules for Selenium Grid/Selenoid and ChurchCRM, plus three new Windows persistence modules targeting Telemetry scheduled tasks, PowerShell profiles, and Microsoft BITS); a critical missing-authentication vulnerability in Nginx UI (CVE-2026-33032, CVSS 9.8); a ClickFix phishing campaign impersonating a Claude installer; and the
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- e201d5f53bc42e3f17748339c90d686c1ce0b73f86111e162d4d1b10bfe425e9
- Enrichment time
- 2026-04-20T07:23:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.