Metasploit Wrap-Up 04/17/2026

2026-04-19T07:23:44Ze6ff1953d416cd84b08bf75a7358cc3ffdd5a19624b705e74408e6beb637e40f
CVE-2026-28501CVE-2026-28517CVE-2026-33032avideoclickfixcloud-detectionexploitincident-responsemetasploitnginx-uiopendcimpatch-tuesdaypersistencephishingpowershellrceremediationsocsql-injectiontelemetryunauthenticatedwindows-bits

What happened

Rapid7 blog roundup covering multiple security developments: Metasploit Framework added seven new modules (including unauthenticated SQLi credential-dump for AVideo — CVE-2026-28501, an openDCIM install.php SQLi to RCE exploit — CVE-2026-28517, RCE modules for Selenium Grid/Selenoid and ChurchCRM, and three new Windows persistence modules targeting telemetry scheduled tasks, PowerShell profiles, and BITS). Separate Rapid7 posts highlight a critical missing-authentication vulnerability in Nginx UI (CVE-2026-33032, CVSS 9.8), an observed ClickFix phishing campaign masquerading as a Claude AI “up

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
e6ff1953d416cd84b08bf75a7358cc3ffdd5a19624b705e74408e6beb637e40f
Enrichment time
2026-04-19T07:23:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.