Weekly Metasploit Update: New Kerberos/Certificate tracing options, and multiple new modules
2026-06-13T19:23:45Z•54987fbfd1a1113b0a50872522a16f511f42bba215d0300efbb140744f88750f
CVE-2026-10520CVE-2026-10523CVE-2026-35273LLManthropicauthentication bypassautomated threat huntingcertificatecriminal ai-as-a-servicedebuggingivantiivanti sentrykerberosmetasploitmicrosoftoraclepatch tuesdaypeoplesoftpeopletoolsproject glasswingremote code executionssrfthreat huntingunderground ai
What happened
Rapid7 blog roundup (June 2026) covering: a Metasploit update that adds KerberosTicketTrace and CertificateTrace debugging options; active exploitation of an Oracle PeopleSoft zero-day (CVE-2026-35273) — a remotely exploitable, unauthenticated RCE (CVSS 9.8) tied to PeopleTools Updates Environment Management; two critical Ivanti Sentry vulnerabilities (CVE-2026-10520 — unauthenticated OS command injection RCE, CVSS 10.0; and CVE-2026-10523 — authentication bypass allowing admin account creation, CVSS 9.9); discussion of the June 2026 Microsoft Patch Tuesday (~200 vulnerabilities) and uncoordin
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- 54987fbfd1a1113b0a50872522a16f511f42bba215d0300efbb140744f88750f
- Enrichment time
- 2026-06-13T19:23:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.