logo

Metasploit Releases 7 New Exploit Modules covering FreePBX, Cacti and SmarterMail

ID: aa15847f-27bc-525d-9134-1c1ad61fbbe0

STIX ID: report--aa15847f-27bc-525d-9134-1c1ad61fbbe0

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-01-31

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Metasploit's latest release introduces seven new modules that enable unauthenticated and chained attacks against widely used infrastructure: FreePBX (authentication bypass CVE-2025-66039 chained to SQLi CVE-2025-61675 or file upload CVE-2025-61678 to achieve RCE or admin creation), Cacti (unauthenticated RCE via CVE-2025-24367), and SmarterMail (unauthenticated file upload/path traversal CVE-2025-52691), along with persistence modules for Burp Suite and consolidated SSH key persistence; organizations should prioritize patching, hardening exposed services, and auditing for signs of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.