Metasploit Wrap-Up 04/17/2026
2026-04-19T07:23:44Z•e6ff1953d416cd84b08bf75a7358cc3ffdd5a19624b705e74408e6beb637e40f
CVE-2026-28501CVE-2026-28517CVE-2026-33032avideoclickfixcloud-detectionexploitincident-responsemetasploitnginx-uiopendcimpatch-tuesdaypersistencephishingpowershellrceremediationsocsql-injectiontelemetryunauthenticatedwindows-bits
What happened
Rapid7 blog roundup covering multiple security developments: Metasploit Framework added seven new modules (including unauthenticated SQLi credential-dump for AVideo — CVE-2026-28501, an openDCIM install.php SQLi to RCE exploit — CVE-2026-28517, RCE modules for Selenium Grid/Selenoid and ChurchCRM, and three new Windows persistence modules targeting telemetry scheduled tasks, PowerShell profiles, and BITS). Separate Rapid7 posts highlight a critical missing-authentication vulnerability in Nginx UI (CVE-2026-33032, CVSS 9.8), an observed ClickFix phishing campaign masquerading as a Claude AI “up
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- e6ff1953d416cd84b08bf75a7358cc3ffdd5a19624b705e74408e6beb637e40f
- Enrichment time
- 2026-04-19T07:23:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.