CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Weekly Metasploit Update: Modules for Audiobookshelf, LiteLLM, Next.js, Dalfox and more

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 367

As cited

Copy frozen at (site build).

vulnerabilities

Weekly Metasploit Update: Modules for Audiobookshelf, LiteLLM, Next.js, Dalfox and more

Metasploit Framework released new modules for detecting and exploiting vulnerabilities in Audiobookshelf, LiteLLM Proxy, Next.js, and Dalfox. The updates include authentication bypass scanners, a SQL injection detection module, and a remote code execution exploit, along with improvements to bruteforce-related modules. The project is also soliciting feedback on planned changes to evasion capabilities until July 1, 2026.

Why it matters: Security practitioners using Metasploit should update to leverage detection modules for the critical CVE-2026-42208 (CISA KEV, CVSS 9.3) in LiteLLM and high-severity authorization bypasses in Next.js (CVSS 9.1) and Audiobookshelf to assess their environments, and have an RCE exploit available for Dalfox versions 2.12.0 and earlier.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Weekly Metasploit Update: Modules for Audiobookshelf, LiteLLM, Next.js, Dalfox and more

Metasploit Framework released new modules for detecting and exploiting vulnerabilities in Audiobookshelf, LiteLLM Proxy, Next.js, and Dalfox. The updates include authentication bypass scanners, a SQL injection detection module, and a remote code execution exploit, along with improvements to bruteforce-related modules. The project is also soliciting feedback on planned changes to evasion capabilities until July 1, 2026.

Why it matters: Security practitioners using Metasploit should update to leverage detection modules for the critical CVE-2026-42208 (CISA KEV, CVSS 9.3) in LiteLLM and high-severity authorization bypasses in Next.js (CVSS 9.1) and Audiobookshelf to assess their environments, and have an RCE exploit available for Dalfox versions 2.12.0 and earlier.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary