Metasploit Wrap-Up 04/03/2026
2026-04-04T07:23:45Z•183cdb457f94a6580af912c862ed7eb9ceb140f3810f3d36a1b7be9fc202f1b9
IABRDPUserInitMprLogonScriptVPN','RDWeb','visibility-gap','AI-MDRbpfbpfd00reclipse-cheescposfreeScoutgeneric-http-cmd-execgrav-cmshttp-shellicmp-tunnelinitial-access-brokerkernel-backdoormetasploit-frameworkmeterpreterntlm-relaypersistenceprinter-exploitremote-code-executionrubySMBtelecom-infrastructureunauthenticated-rcewindows-registry
What happened
Rapid7 published multiple security updates and research in late Mar–Apr 2026: Metasploit added several new HTTP/HTTPS CMD payloads and exploit modules enabling unauthenticated RCE (notably FreeScout .htaccess ZWSP bypass and Grav CMS RCE), a generic multi/http/os_cmd_exec module for HTTP-to-system command execution (can yield Meterpreter), and a new Windows persistence technique abusing HKCU\Environment\UserInitMprLogonScript. Additional Metasploit improvements include enhanced SMB NTLM relaying (RubySMB client changes) and new auxiliary/exploit modules (ESC/POS printer command injection and E
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- 183cdb457f94a6580af912c862ed7eb9ceb140f3810f3d36a1b7be9fc202f1b9
- Enrichment time
- 2026-04-04T07:23:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.