
this could have been a feature, not a bug 😀😀 🟧 CVE-2026-7373, CVSS: 8.5 (High) Metasploit Pro version, Rapid7 a local privilege escalation vulnerability affecting Windows installations the metasploitPostgreSQL service attempts to load an OpenSSL configuration file from a non-existent, user-writable directory, allowing arbitrary command execution via a crafted file this permits an unprivileged user to bypass security controls and achieve full host compromise with SYSTEM-level access https://docs.rapid7.com/insight/release-notes-5.0.0-2026051301/#:~:text=Pro%3A%20We%20fixed,vulnerability%20to%20Rapid7.
Post summary
The post highlights a Metasploit Pro exploit for CVE-2026-7373, a Windows local privilege escalation via a crafted OpenSSL config file, with no evidence of active exploitation or available patches.

