Metasploit Wrap-Up 04/10/2026

2026-04-11T07:23:58Z4949df835817194c5007f51e6bb40d170467dacfcf5b0b3b58dae3ba545dbe99
ADCSAI vulnerability discoveryActive Directory Certificate ServicesCVE-2025-59718CVE-2025-59719CVE-2026-20127Cisco Catalyst SD‑WANFortiGateFreeScoutProject GlasswingRCEexploitation-in-the-wildincident responsemetasploitmodule releasemsfvenomosTicketzero-day

What happened

Rapid7 blog roundup: Metasploit received multiple new modules and improvements (including an msfvenom startup speedup). Notable module additions include an AD/CS Authenticated Web Enrollment auxiliary module and an auxiliary module for a Cisco Catalyst SD‑WAN Controller authentication bypass that maps to CVE‑2026‑20127 (recently observed exploited in the wild). Rapid7’s IR team also published findings on active exploitation of FortiGate vulnerabilities (CVE‑2025‑59718 and related CVE‑2025‑59719) that enable SSO signature/verification bypasses and were used to pivot into internal networks. The

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
4949df835817194c5007f51e6bb40d170467dacfcf5b0b3b58dae3ba545dbe99
Enrichment time
2026-04-11T07:23:58Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.