Metasploit Wrap-Up 04/10/2026
2026-04-13T07:23:55Z•85ae2de57459f6b18a218b647a7d620f4a6aa19976d62f17c36f5703d6aa1039
ADCSAI-driven vulnerability discoveryActive Directory Certificate ServicesCVE-2025-59718CVE-2025-59719CVE-2026-20127Cisco Catalyst SD-WANFortiGateIncident ResponseMetasploitProject GlasswingRCEWindows persistenceexploited in the wildmsfvenomvisibility
What happened
Rapid7 posts (Apr 2026) highlight multiple security developments: Metasploit Framework received new modules (AD/CS Web Enrollment certificate issuance, Cisco Catalyst SD‑WAN Controller authentication bypass module for CVE-2026-20127—recently exploited in the wild—along with osTicket, FreeScout and Grav CMS RCE modules), Windows persistence techniques, and msfvenom startup speed improvements. Rapid7 IR describes exploitation of FortiGate appliances (CVE-2025-59718, with related coverage including CVE-2025-59719) enabling SSO bypass and lateral movement. Additional commentary warns that AI tools
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- 85ae2de57459f6b18a218b647a7d620f4a6aa19976d62f17c36f5703d6aa1039
- Enrichment time
- 2026-04-13T07:23:55Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.