LIVE · cybersecurity feed
Live wire
CVE-2025-66516high

Metasploit Wrap Up: This One Goes to Sixteen!

This One Goes to Sixteen! Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit modules, and not to be outdone, we even have a Metasploit scanner to watch the watchers! New module content (16) Elasticsearch ingest-attachment Apache Tika XFA XXE Local File Read Auth

zeroday.news ·

A recent update to the Metasploit framework has introduced sixteen new modules, including ten exploit modules, five of which address vulnerabilities listed on the CISA Known Exploited Vulnerabilities (KEV) catalog. The new exploits target products from Cisco, PaperCut, SonicWall, JetBrains, and Langflow, among others.

One of the significant additions is an exploit module for CVE-2026-20079, an unauthenticated authentication bypass vulnerability affecting Cisco Secure Firewall Management Center (FMC). This allows for remote code execution (RCE) on vulnerable systems.

For SonicWall SMA1000, a new module addresses a chain of zero-day exploits (CVE-2026-83548, SMA1000-9427, and CVE-2026-83549) that were reportedly exploited in the wild in early September. This chain leverages a server-side request forgery (SSRF) to bypass authentication, an RCE with low privileges via CouchDB read/write primitives, and a command injection in `cmsSnmpTrap.sh` for root-level RCE. SonicWall has confirmed that version 12.5.0-02952 remediates this exploit chain.

JetBrains TeamCity is also targeted with a new unauthenticated RCE exploit module, CVE-2026-63077. This vulnerability stems from an unsafe XStream deserialization flaw within the agent polling protocol, enabling the execution of a one-shot JSP payload on the server. The module supports both Windows and Linux targets and includes cleanup logic to remove the fake build agent created during exploitation.

PaperCut NG/MF is affected by an exploit chain (CVE-2026-81578 and CVE-2026-82078) that was reported as a zero-day actively exploited in the wild. A new Metasploit module has been added to exploit these vulnerabilities, which lead to unauthenticated RCE.

Other notable exploit modules include CVE-2026-19295, an authenticated RCE vulnerability in Langflow versions 1.10.0 and below, and CVE-2026-23744, an unauthenticated command execution vulnerability in MCPJam Inspector via the `/api/mcp/connect` endpoint. The latter allows remote attackers to execute operating system commands by manipulating a JSON `serverConfig` object.

SimpleHelp versions 5.5.0 through 5.5.15 are vulnerable to CVE-2026-48558, an OIDC authentication bypass leading to remote code execution. Additionally, an unauthenticated RCE vulnerability in SPIP versions up to 4.4.21, affecting the forum autosave session handler, has been added. This allows arbitrary PHP code storage in a session variable, which is then executed by the template engine. No CVE has been assigned to the SPIP autosave vulnerability yet.

Next.js applications hosted on Windows servers are susceptible to CVE-2026-75604, an RCE vulnerability affecting versions 13.4.0 through 15.5.24, and 16.0.0 through 16.3.3. This allows for arbitrary code execution through specially crafted requests.

Beyond exploits, the update also features several auxiliary and evasion modules. These include a scanner for CVE-2025-54988/CVE-2025-66516, an XML External Entity (XXE) vulnerability in Apache Tika's XFA parser exposed through the Elasticsearch attachment ingest processor. Another auxiliary module addresses a blind SQL injection in SPIP's date column escaping logic. A new scanner module can detect Metasploit reverse handlers on target ports, identifying the type of shell they would deliver.

An auxiliary module, `esc8_kerberos`, leverages CVE-2026-20929 to exploit AD CS Web Enrollment (ESC8). This module captures an SMB2 AP-REQ from a coerced client and replays the authentication to the target certificate server over HTTP, allowing an attacker to obtain a certificate for the victim and a valid Kerberos TGT without credentials. An evasion module for Linux x64 environments performs runtime checks to detect sandboxes or virtual machines and aborts execution if detected.

Finally, two new Windows persistence modules have been added: one leveraging the `BootVerificationProgram` registry key and another registering a custom Time Provider DLL.

vulnerabilities in this storyCVE-2025-66516CVE-2025-54988CVE-2026-20929CVE-2026-20079CVE-2026-83549CVE-2026-83548CVE-2026-63077CVE-2026-19295CVE-2026-23744CVE-2026-81578CVE-2026-82078CVE-2026-48558CVE-2026-75604
breachvulnerabilityzero-daypatchnation-state
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

malware

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

'Enemies of the regime' on notice

patch

Before You Patch. Why Patch Reliability Matters for Confident Deployment

Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operational risk that can accompany security patching. Qualys TruRisk Eliminate classified both updates as Low Reliability, signaling the need for additional validation before production deployment. Patch Reliability helps IT and s