Metasploit Wrap-Up 04/10/2026
2026-04-11T07:23:58Z•4949df835817194c5007f51e6bb40d170467dacfcf5b0b3b58dae3ba545dbe99
ADCSAI vulnerability discoveryActive Directory Certificate ServicesCVE-2025-59718CVE-2025-59719CVE-2026-20127Cisco Catalyst SD‑WANFortiGateFreeScoutProject GlasswingRCEexploitation-in-the-wildincident responsemetasploitmodule releasemsfvenomosTicketzero-day
What happened
Rapid7 blog roundup: Metasploit received multiple new modules and improvements (including an msfvenom startup speedup). Notable module additions include an AD/CS Authenticated Web Enrollment auxiliary module and an auxiliary module for a Cisco Catalyst SD‑WAN Controller authentication bypass that maps to CVE‑2026‑20127 (recently observed exploited in the wild). Rapid7’s IR team also published findings on active exploitation of FortiGate vulnerabilities (CVE‑2025‑59718 and related CVE‑2025‑59719) that enable SSO signature/verification bypasses and were used to pivot into internal networks. The
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- 4949df835817194c5007f51e6bb40d170467dacfcf5b0b3b58dae3ba545dbe99
- Enrichment time
- 2026-04-11T07:23:58Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.