Exploit discussion active in current signal (2 latest mentions)
Immediate actions
Patch getgrav grav systems immediately
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: High priority (within 72h)
NVD description
A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the /admin/tools/direct-install interface. Once uploaded, the plugin is automatically extracted and loaded, allowing arbitrary PHP code execution and reverse shell access.
Metasploit Framework is here with 5 new modules! Exploits for FreeScout (CVE-2026-28289) and Grav CMS (CVE-2025-50286) RCEs, plus a generic HTTP command execution module and a new Windows persistence technique. We also have a slew of bug fixes and enhancements including SOCKS proxy performance improvements #Metasploit https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-04-03-2026/1
Post summary
Rapid7’s Metasploit release introduces new exploit modules for CVE‑2026‑28289 and CVE‑2025‑50286, offering RCE capabilities, but there is no evidence of current exploitation in the wild.
📡 Strategic Insight: Metasploit Wrap-Up 04/03/2026
📅 Context: Rapid7 released Metasploit Framework 6.4.125 on 2026-04-03; adds five new modules including FreeScout unauthenticated RCE, Grav CMS plugin-upload RCE (CVE-2025-50286), generic multi/http/os_cmd_exec, Windows HKCU\Environment\UserInitMprLogonScript persistence, and new HTTP/HTTPS CMD payload adapters for Windows x86/x64. Also removes legacy modules, improves docs and fixes crashes/warnings.
📌 Key Takeaways:
- New exploit modules: unauthenticated RCE for FreeScout; authenticated plugin-upload RCE for Grav CMS (CVE-2025-50286). Prioritize patching and hardening.
- Generic multi/http/os_cmd_exec expands ability to target HTTP endpoints that lead to OS command execution; review input handling and detect command-exec patterns.
- Windows persistence via HKCU\Environment\UserInitMprLogonScript runs payloads at interactive logon; monitor and alert on changes to that registry value and related logon artifacts.
- HTTP/HTTPS CMD payload adapters for Windows x86/x64 expand delivery options; tune network detection for anomalous fetch patterns and unexpected GET/POSTs.
- Quality/reliability improvements make these tools more usable; defenders should assume higher reliability in adversary emulation.
📝 Summary:
This Metasploit update lowers the bar for exploiting plugin upload and HTTP-based command exec vectors and introduces a user-logon persistence trick, increasing the need for targeted detection and patching.
🛡️ Actionable Recommendations:
- Update authorized assessment tooling (msfupdate or latest repo) to obtain new modules for testing.
- Patch FreeScout and Grav instances, and restrict and harden plugin upload and install endpoints.
- Audit webapps for unsafe eval or exec patterns and enforce input validation and least-privilege execution contexts.
- Monitor and alert on writes or unexpected values for HKCU\Environment\UserInitMprLogonScript and related logon activity.
- Update IDS and endpoint rules to flag behaviors introduced by multi/http/os_cmd_exec and the CMD payload fetch adapters.
- Tune network detection for command payload fetches over HTTP/HTTPS and anomalous endpoint fetches.
🔗 Related Resources:
- https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-04-03-2026
- https://github.com/rapid7/metasploit-framework/compare/6.4.124...6.4.125
- https://github.com/rapid7/metasploit-framework/pull/21069
- https://github.com/rapid7/metasploit-framework/pull/21029
- https://github.com/rapid7/metasploit-framework/pull/21172
🏷 Tags: #Metasploit#Exploitation#RCE#Persistence#Payloads#Penetration-Testing #Threat-Hunting #Security-Updates #CyberSecurity
Post summary
Metasploit 6.4.125 introduces functional exploit modules that lower the barrier for exploiting RCEs in FreeScout and Grav CMS, along with new persistence and command‑execution capabilities, highlighting an expanded attacker toolkit.