As cited
Copy frozen at (site build).
vulnerabilities
Weekly Metasploit Update: Exploits for FlowiseAI CSV Agent and MacOS Package Kit
Metasploit released new exploit modules for three vulnerabilities: FlowiseAI CSV Agent (CVE-2026-41264), an unauthenticated remote code execution flaw allowing attackers to upload malicious CSV files; macOS PackageKit (CVE-2024-27822), a privilege escalation vulnerability in ZSH environment handling; and Apache .htaccess persistence for Linux systems. The update also includes enhancements to FTP fingerprinting, library reloading, MCP Server tools, and certificate tracing functionality.
Why it matters: Security practitioners should review patches for Flowise versions 1.3.0 through 3.0.13 and macOS versions 14.4, 13.6.6, 12.7.4, and 11 or earlier, as these vulnerabilities enable unauthenticated remote code execution and local privilege escalation respectively.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Weekly Metasploit Update: Exploits for FlowiseAI CSV Agent and MacOS Package Kit
Metasploit released new exploit modules for three vulnerabilities: FlowiseAI CSV Agent (CVE-2026-41264), an unauthenticated remote code execution flaw allowing attackers to upload malicious CSV files; macOS PackageKit (CVE-2024-27822), a privilege escalation vulnerability in ZSH environment handling; and Apache .htaccess persistence for Linux systems. The update also includes enhancements to FTP fingerprinting, library reloading, MCP Server tools, and certificate tracing functionality.
Why it matters: Security practitioners should review patches for Flowise versions 1.3.0 through 3.0.13 and macOS versions 14.4, 13.6.6, 12.7.4, and 11 or earlier, as these vulnerabilities enable unauthenticated remote code execution and local privilege escalation respectively.
- Source published
- First seen by Cybersecurity Tracker