Metasploit Wrap-Up 05/01/2026

2026-05-02T07:23:47Z9da6aface72d27e513293ac31edb4a275a6736d884b95b957440838ddf460c5d
AARCH64AMD64CVE-2024-46987CVE-2026-31431CVE-2026-41940CVSS 9.8Camaleon CMSCopy FailMCPModel Context Protocolauthentication bypasscPaneldirectory traversalexploit modulelinux kernellocal privilege escalationmetasploitmsfmcpdpage cache su replacementrapid7threat landscape

What happened

Rapid7 updates: Metasploit added a read-only MCP server (msfmcpd) to expose standardized query tools for AI integrations and shipped new module content and improvements. A high-profile Linux local privilege escalation dubbed “Copy Fail” (CVE-2026-31431) has a public PoC and Metasploit local exploit that targets AMD64 and AARCH64 by manipulating the page cache to replace ‘su’ with a small ELF payload. cPanel/WHM received a critical authentication bypass patch (CVE-2026-41940, CVSS 9.8) that allowed unauthenticated remote administrative access. Additional module content includes a Camaleon CMS

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
9da6aface72d27e513293ac31edb4a275a6736d884b95b957440838ddf460c5d
Enrichment time
2026-05-02T07:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Metasploit Wrap-Up 05/01/2026 · Baitaphish