Metasploit Wrap-Up 04/17/2026

2026-04-20T07:23:44Ze201d5f53bc42e3f17748339c90d686c1ce0b73f86111e162d4d1b10bfe425e9
avideochurchcrmclickfixexploit-modulesmetasploitnginx-uiopendcimpatch-tuesdaypersistencephishingrceselenium-gridsql-injectionvulnerability-managementwindows-persistence

What happened

Collection of Rapid7 blog posts (April 2026) covering multiple security topics: Metasploit Framework additions (seven new modules including unauthenticated SQLi credential dump for AVideo - CVE-2026-28501, an openDCIM install.php SQLi→RCE exploit - CVE-2026-28517, RCE modules for Selenium Grid/Selenoid and ChurchCRM, plus three new Windows persistence modules targeting Telemetry scheduled tasks, PowerShell profiles, and Microsoft BITS); a critical missing-authentication vulnerability in Nginx UI (CVE-2026-33032, CVSS 9.8); a ClickFix phishing campaign impersonating a Claude installer; and the

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
e201d5f53bc42e3f17748339c90d686c1ce0b73f86111e162d4d1b10bfe425e9
Enrichment time
2026-04-20T07:23:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Metasploit Wrap-Up 04/17/2026 · Baitaphish