Metasploit Wrap-Up 04/25/2026

2026-04-27T19:23:54Zeb193e71faacb101a7d37472e595449c511de15060e0790f31496b5a3ddd1f9e
AICVE-2024-46987CVE-2026-28501CVE-2026-28517ESXiMCPProject GlasswingSMBTorWindowsavideobulk exportcamaleonexploitkybermetasploitopenDCIMransomwarerapid7software supply chainvulnerability

What happened

Rapid7 posted a set of mid‑April 2026 updates covering multiple topics: Metasploit Framework improvements (more transparent check-method reasoning and better SMB v1 version detection) and several new Metasploit modules, including an auxiliary module for Camaleon CMS directory traversal (CVE-2024-46987), an unauthenticated SQLi credential‑dump module for AVideo (CVE-2026-28501), and an openDCIM install.php SQLi→RCE exploit (CVE-2026-28517). Rapid7 also published a detailed analysis of Kyber ransomware showing coordinated dual‑variant campaigns targeting VMware ESXi (datastore encryption, VM/GUI

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
eb193e71faacb101a7d37472e595449c511de15060e0790f31496b5a3ddd1f9e
Enrichment time
2026-04-27T19:23:54Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Metasploit Wrap-Up 04/25/2026 · Baitaphish