ZeroHour

Source: Metasploit Framework commits

2 stories in the last 30d

add a DefangedMode advanced options as teh exploit modifies the targe…

A Metasploit Framework commit adds a DefangedMode advanced option to an exploit module that modifies the target host configuration.

The commit introduces a DefangedMode advanced option so that the exploit's modification of the target configuration runs only explicitly, making the behavior visible to the user. No target product, affected software, or CVE identifier is named in the commit message.

Metasploit Framework commits · 14d agoExploit / PoC1

SimpleHelp OpenID Connect Auth Bypass to RCE [CVE-2026-48558]

Metasploit adds a module chaining SimpleHelp OpenID Connect authentication bypass to remote code execution, tracked as CVE-2026-48558.

A commit to the Rapid7 Metasploit Framework (dee04cdb) adds an exploit module for CVE-2026-48558, an OpenID Connect authentication bypass in SimpleHelp that can be escalated to remote code execution. SimpleHelp is widely deployed remote access and remote support software, making the auth bypass a serious exposure for exposed deployments. The commit provides public exploit code but the listing does not state observed exploitation.