Metasploit Wrap-Up 04/10/2026

2026-04-10T19:23:51Z91ef6a0689b5157b8d600d7400c326a4bb87fdaf694b5aa5c361c2d4a0a054cb
ADCSAI-vulnerability-discoveryCVE-2025-59718CVE-2025-59719CVE-2026-20127Cisco Catalyst SD-WANFortiGateFreeScoutGrav CMSLDAPRCEWindows persistenceincident-responsemetasploitmsfvenomosTicketproject-glasswingvisibility

What happened

Rapid7 blog roundup (Apr 2026): updates to Metasploit Framework including new modules (AD/CS Web Enrollment certificate issuance, Cisco Catalyst SD‑WAN Controller authentication bypass, FreeScout/Grav/osTicket exploit modules), Windows persistence improvements, LDAP/ADCS service reporting, and a ~2x msfvenom startup speedup. The Cisco SD‑WAN module targets an authentication bypass (CVE-2026-20127) noted as recently exploited in the wild. Rapid7 IR details exploitation of FortiGate vulnerabilities (CVE-2025-59718 and related CVE-2025-59719) leading to SSO bypass and lateral compromise. The feed

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
91ef6a0689b5157b8d600d7400c326a4bb87fdaf694b5aa5c361c2d4a0a054cb
Enrichment time
2026-04-10T19:23:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.