Metasploit Wrap-Up 04/03/2026

2026-04-07T07:23:55Z4eb7c969fe7bb7b00d34cbcd743338c10e6642429b24ef08053e2e88bb4a54be
CVE-2026-23767IABUserInitMprLogonScriptbpfdooreclipse-cheepson-printersescposfreescoutgrav-cmshkcuhttpShellicmpinitial-access-brokerskernel-backdoormetasploitntlm-relayos_cmd_execpersistencercerdpregistrysmbstateless-c2telecom-infrastructurevpn','rdweb','visibility','ai-mdr

What happened

Rapid7 published multiple posts covering new Metasploit modules and exploit additions (unauthenticated FreeScout .htaccess RCE, Grav and other RCE modules, a generic multi/http/os_cmd_exec module, new HTTP/HTTPS CMD payloads, improved SMB NTLM relaying, and a Windows persistence technique abusing HKCU\Environment\UserInitMprLogonScript). A Metasploit auxiliary module targets networked Epson-compatible ESC/POS printers via CVE-2026-23767. Rapid7 Labs released a whitepaper describing seven new stealthy BPFDoor kernel-level backdoor variants (notably httpShell and icmpShell) that use BPF and stat

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
4eb7c969fe7bb7b00d34cbcd743338c10e6642429b24ef08053e2e88bb4a54be
Enrichment time
2026-04-07T07:23:55Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.