Weekly Metasploit Update: New Kerberos/Certificate tracing options, and multiple new modules
2026-06-15T07:23:47Z•0736e491e4422b5c3be19d774af62232b997c57be7ab003e62b5d5bebda170c5
Anthropic Project GlasswingCertificateTraceIvanti SentryKerberosLLMMetasploitMicrosoft Patch TuesdayNightmare EclipseOS command injectionOracle PeopleSoftPeopleToolsRCESSRFTrendAIZero Day Initiativeauthentication bypasscriminal AI-as-a-servicedebuggingdisclosurethreat hunting
What happened
Rapid7 published multiple posts covering: a Metasploit update that adds KerberosTicketTrace and CertificateTrace debugging options; active exploitation of an Oracle PeopleSoft zero-day (CVE-2026-35273) — a remotely exploitable RCE (CVSS 9.8) in PeopleTools 8.61/8.62 with an out-of-band patch; two critical Ivanti Sentry flaws (CVE-2026-10520 — unauthenticated OS command injection RCE with CVSS 10.0, and CVE-2026-10523 — authentication bypass allowing creation of admin accounts, CVSS 9.9); June 2026 Microsoft Patch Tuesday (≈200 vulnerabilities) and uncoordinated public disclosures by an active/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- 0736e491e4422b5c3be19d774af62232b997c57be7ab003e62b5d5bebda170c5
- Enrichment time
- 2026-06-15T07:23:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.