Metasploit

@metasploit-r7.bsky.social

Official account of the Metasploit Project, part of the Rapid7 family. Mastodon: @metasploit@infosec.exchange Slack: http://metasploit.com/slack

We'll be demoing Metasploit 6.5 at Black Hat Arsenal Station 4 tomorrow, August 5th at 4PM. Be sure to stop by if you're attending to see the latest features in action and chat with some of the maintainers.

Some neat n-day vulnerability analysis of Citrix NetScaler Console CVE-2024-6235 via Calum Hutton — the vuln allows an unauthenticated attacker to obtain an admin-level session ID from an internal API and use this to create other admin users on the system. attackerkb.com/assessments/...

chutton-r7's assessment of CVE-2024-6235 | AttackerKB

On July 9, 2024, Citrix disclosed CVE-2024-6235, a sensitive information disclosure vulnerability affecting NetScaler Console. While “information disclosure” s…

attackerkb.com

We have just published our AttackerKB @rapid7.com Analysis of CVE-2025-22457, an unauthenticated stack based buffer overflow in Ivanti Connect Secure. Difficult to exploit due to severe character restrictions, we detail our full RCE technique here: attackerkb.com/topics/0ybGQ...

CVE-2025-22457 | AttackerKB

On April 3, 2025, Ivanti published an advisory for CVE-2025-22457, an unauthenticated remote code execution vulnerability due to a stack based buffer overflow.…

attackerkb.com

Rapid7 analysis of Apache #Struts 2 CVE-2024-53677 here via research lead Ryan Emmons — highlights: * No, this isn't really being successfully exploited in the wild * Payloads need to be customized to the target * The 'fixed' version *does not* remediate the vuln attackerkb.com/assessments/...

remmons-r7's assessment of CVE-2024-53677 | AttackerKB

CVE-2024-53677 is a flawed upload logic vulnerability in Apache Struts 2. The vulnerability permits an attacker to override internal file upload variables in a…

attackerkb.com

It's raining RCEs in this week's #Metasploit wrap-up 🌧️ 7 new modules to help you get RCE on Primefaces, Moodle, WordPress Really Simple SSL, and CyberPanel, as well as change passwords via the LDAP and SMB protocols. www.rapid7.com/blog/post/20...

Metasploit Weekly Wrap-Up: 12/13/2024 | Rapid7 Blog

This weekly release includes RCEs for Moodle e-Learning platform, Primefaces, WordPress Really Simple SSL & CyberPanel along with two other modules.

rapid7.com