Metasploit Wrap-Up 04/10/2026
2026-04-12T07:23:49Z•34ba12835229391b0af22a1ea693eedccc345787abd495439ef4855891a35b0e
adcsai-vulnerability-discoveryanthropicauthentication-bypassciscocisco-sd-wanfortigatefreescoutgrav-cmsincident-responseldapmdrmetasploitmsfvenomosticketproject-glasswingrcesd-wansecurity-operationsvisibilityweb-enrollmentwindows-persistence
What happened
A set of Rapid7 blog posts covering: Metasploit Framework updates (new modules and msfvenom startup speedups) including modules for AD/CS Web Enrollment certificate issuance, Cisco Catalyst SD‑WAN Controller authentication bypass (CVE-2026-20127, reported exploited in the wild), FreeScout and Grav unauthenticated RCE modules, and other Windows persistence/LDAP/ADCS tooling. A Rapid7 IR writeup details exploitation of FortiGate SSO signature verification vulnerabilities (CVE-2025-59718 and related CVE-2025-59719) and attack progression/detection guidance. An analysis of Anthropic’s Project Glas
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- 34ba12835229391b0af22a1ea693eedccc345787abd495439ef4855891a35b0e
- Enrichment time
- 2026-04-12T07:23:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.