Metasploit Wrap-Up 05/08/2026

2026-05-10T19:23:46Z41558a163e6d2d150fcbd74a37771b6f2dc8339f5ca532d5f9368f89ba715f8e
CVE-1999-0497CVE-2026-0300CWE-787PAN-OSPalo Altoanonymous-ftpbuffer-overflowchaos-ransomwarecopy_faildeserializationexploit-moduleexploited-in-the-wildftp-scannermetasploitmuddywaterremote-code-executionshiro_remembermestate-sponsored

What happened

Rapid7 blog roundup (08 May 2026) highlights multiple security updates and research: Metasploit received functional improvements (Copy Fail exploit payload fixes, added linux/armle support, and enhancements to exploit/multi/http/shiro_rememberme_v124_deserialize to adjust deserialization chains) and a revamped anonymous FTP scanner (references CVE-1999-0497). Rapid7 published an ETR on a critical, publically exploited PAN‑OS vulnerability (CVE-2026-0300): an unauthenticated buffer overflow (CWE‑787) in the User‑ID Authentication Portal allowing remote root code execution (CVSSv4 9.3) on PA‑/VM

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
41558a163e6d2d150fcbd74a37771b6f2dc8339f5ca532d5f9368f89ba715f8e
Enrichment time
2026-05-10T19:23:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Metasploit Wrap-Up 05/08/2026 · Baitaphish