Metasploit Wrap-Up 04/25/2026
2026-04-27T19:23:54Z•eb193e71faacb101a7d37472e595449c511de15060e0790f31496b5a3ddd1f9e
AICVE-2024-46987CVE-2026-28501CVE-2026-28517ESXiMCPProject GlasswingSMBTorWindowsavideobulk exportcamaleonexploitkybermetasploitopenDCIMransomwarerapid7software supply chainvulnerability
What happened
Rapid7 posted a set of mid‑April 2026 updates covering multiple topics: Metasploit Framework improvements (more transparent check-method reasoning and better SMB v1 version detection) and several new Metasploit modules, including an auxiliary module for Camaleon CMS directory traversal (CVE-2024-46987), an unauthenticated SQLi credential‑dump module for AVideo (CVE-2026-28501), and an openDCIM install.php SQLi→RCE exploit (CVE-2026-28517). Rapid7 also published a detailed analysis of Kyber ransomware showing coordinated dual‑variant campaigns targeting VMware ESXi (datastore encryption, VM/GUI
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- eb193e71faacb101a7d37472e595449c511de15060e0790f31496b5a3ddd1f9e
- Enrichment time
- 2026-04-27T19:23:54Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.