Metasploit Wrap-Up 05/15/2026

2026-05-17T19:23:49Z90eeb641eae2070a774fd6e95da4c2e42e3df5737a500e96492575924969e57e
authentication-bypassciscodolibarrgestioipmarvellmicrosoftmodeloratnetlogonpalo-altopan-ospatch-tuesdaypath-traversalpersistencephishingprivilege-escalationrapid7remote-code-executionsd-wanteamsvim-pluginweb-upload

What happened

Rapid7 blog roundup covering multiple high-impact disclosures and incidents: a Metasploit write-up on malicious Vim plugin persistence; Palo Alto PAN-OS authentication bypass (CVE-2026-0265, High/7.2) affecting CAS-enabled logins; a critical Cisco Catalyst SD‑WAN Controller authentication bypass (CVE-2026-20182, CVSS 10.0) that can allow a remote unauthenticated attacker to become an authenticated peer and perform privileged operations; an enterprise intrusion using ModeloRAT via Microsoft Teams that escalated to domain compromise (abusing CVE-2023-36036 among other techniques); and Microsoftʼ

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
90eeb641eae2070a774fd6e95da4c2e42e3df5737a500e96492575924969e57e
Enrichment time
2026-05-17T19:23:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.