We’re happy to announce that Metasploit Framework had a big week, landing seven new modules alongside various bug fixes and enhancements
https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-04-17-2026/

Metasploit Wrap-Up 04/17/2026
The Metasploit Framework received a major update, introducing seven new modules alongside various bug fixes and enhancements. Four new Remote Code Execution (RCE) exploit modules were added this week. These RCE modules target critical vulnerabilities in AVideo (unauthenticated SQLi for credential dumping), openDCIM (chained SQLi to RCE), ChurchCRM (file upload RCE), and a unified module for unauthenticated Selenium Grid/Selenoid instances. For post-exploitation, three new Windows persistence techniques are now available. These new persistence modules abuse the Windows Telemetry scheduled task, PowerShell profiles, and Microsoft BITS jobs to maintain system access. The update was rounded out with 11 general enhancements, including RISC-V Linux support for fileless payloads, and four resolved bugs.





