Weekly Metasploit Update: New Kerberos/Certificate tracing options, and multiple new modules

2026-06-15T07:23:47Z0736e491e4422b5c3be19d774af62232b997c57be7ab003e62b5d5bebda170c5
Anthropic Project GlasswingCertificateTraceIvanti SentryKerberosLLMMetasploitMicrosoft Patch TuesdayNightmare EclipseOS command injectionOracle PeopleSoftPeopleToolsRCESSRFTrendAIZero Day Initiativeauthentication bypasscriminal AI-as-a-servicedebuggingdisclosurethreat hunting

What happened

Rapid7 published multiple posts covering: a Metasploit update that adds KerberosTicketTrace and CertificateTrace debugging options; active exploitation of an Oracle PeopleSoft zero-day (CVE-2026-35273) — a remotely exploitable RCE (CVSS 9.8) in PeopleTools 8.61/8.62 with an out-of-band patch; two critical Ivanti Sentry flaws (CVE-2026-10520 — unauthenticated OS command injection RCE with CVSS 10.0, and CVE-2026-10523 — authentication bypass allowing creation of admin accounts, CVSS 9.9); June 2026 Microsoft Patch Tuesday (≈200 vulnerabilities) and uncoordinated public disclosures by an active/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
0736e491e4422b5c3be19d774af62232b997c57be7ab003e62b5d5bebda170c5
Enrichment time
2026-06-15T07:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.