Metasploit Wrap-Up 03/27/2026

2026-03-28T19:23:45Za90a29d851f365838ec526c889d58fc2bee943cba5d17f7894a8c17708f15bfe
BPFdoorCVE-2026-23767CVE-2026-3055CVSSCitrix NetScalerESC/POSEpson printersIoT cellular securityNTLM relayingRed MenshenRubySMBSAML IDPSMBmetasploitout-of-bounds readrapid7telecom compromisevulnerability management

What happened

Rapid7 blog posts covering multiple security topics: Metasploit updates (improved SMB NTLM relaying compatibility and new modules), including an auxiliary module exploiting CVE-2026-23767 (unauthenticated ESC/POS command injection against Epson-compatible network printers). Rapid7 also published an advisory on Citrix NetScaler ADC/Gateway out-of-bounds read CVE-2026-3055 (CVSS 9.3) affecting SAML IDP configurations and allowing unauthenticated memory disclosure. Additional research items include detection/analysis of BPFdoor sleeper cells placed in telecom infrastructure by a China-nexus actor

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
a90a29d851f365838ec526c889d58fc2bee943cba5d17f7894a8c17708f15bfe
Enrichment time
2026-03-28T19:23:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.