KEV ✓ (4 z 9) · ransomware EPSS 0.97 (nejvyšší)
Metasploit Wrap Up: Lot of summer shells and fit http profiles
This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce, and for those who like their exploits closer to the bare-metal, the Fragnesia Linux kernel LPE (CVE-2026-46300). Metasploit also got the glow-up of the summer with the new http malleable profiles, MCP functionality and linux multi fetch payloads …
CVE v události 9
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2025-49132 | 10.0 3.1 · GitHub_M | – | 0.55 |
| CVE-2026-15409 | 10.0 3.1 · CISA-ADP | KEV ✓ | 0.85 |
| CVE-2026-27760 | 9.2 4.0 · VulnCheck 8.1 3.1 · VulnCheck | – | 0.35 |
| CVE-2026-29053 | 7.7 3.1 · GitHub_M | – | 0.04 |
| CVE-2026-3891 | 9.8 3.1 · Wordfence | – | 0.25 |
| CVE-2026-46300 | 7.8 3.1 · Linux 7.8 3.1 · redhat-SADP | – | 0.09 |
| CVE-2026-48907 | 10.0 4.0 · Joomla | KEV ✓ | 0.78 |
| CVE-2026-60137 | 9.1 3.1 · CISA-ADP 5.9 3.1 · WPScan | KEV ✓ | 0.78 |
| CVE-2026-63030 | 9.8 3.1 · WPScan 7.5 3.1 · CISA-ADP | KEV ✓ | 0.97 |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE.