Metasploit Wrap-Up 03/27/2026

2026-03-29T07:23:43Za3a0372d4e40f33ffcc8b81f408014b988128a5545ed8c29e2f7ab54ad8d5697
BPFdoorBSI C5CVE-2026-23767CVE-2026-3055CVE-2026-4368CVSS critiqueCitrix NetScalerESC/POSEpson printersIoT cellular exploitationNTLM relayRed MenshenSMBVector Commandexposure managementmetasploittelecom intrusionweb application testing

What happened

This collection of Rapid7 posts covers multiple security developments: Metasploit updates (improved SMB NTLM relaying and new modules, including an auxiliary ESC/POS printer command injector exploiting CVE-2026-23767 and an Eclipse Che unauthenticated RCE module); a critical Citrix NetScaler ADC/Gateway out-of-bounds read (CVE-2026-3055, CVSS 9.3) — advisory also references CVE-2026-4368 — affecting SAML IdP configurations; Rapid7 Labs research on a China-linked actor (Red Menshen) deploying stealthy BPF-based ‘sleeper cell’ implants in telecom networks; a whitepaper on weaponization of GSM/cs

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
a3a0372d4e40f33ffcc8b81f408014b988128a5545ed8c29e2f7ab54ad8d5697
Enrichment time
2026-03-29T07:23:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.