Metasploit Wrap-Up 05/01/2026

2026-05-05T07:23:45Zaa9c2ef4563f85de4f2354a07644c985a846d10203b42b760574a212ea5c7dbb
authentication-bypasscamaleoncopy-failcpaneldirectory-traversalexploitlinux-kernellocal-privilege-escalationmetasploitmodel-context-protocolmsfmcpdrapid7threat-landscapevulnerability-disclosurewhm

What happened

Rapid7 published multiple posts covering new Metasploit features and active vulnerabilities. Highlights: Metasploit added a read-only MCP server (msfmcpd) to expose standardized query tools for AI agents; Metasploit shipped a local exploit for the high-profile Linux kernel logic flaw “Copy Fail” (CVE-2026-31431) enabling LPE on AMD64/AARCH64; Rapid7's ETR details a critical cPanel & WHM authentication bypass (CVE-2026-41940, CVSS 9.8) allowing unauthenticated administrative access; and new module content includes a Camaleon CMS directory traversal (CVE-2024-46987). Other posts discuss the 2026

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
aa9c2ef4563f85de4f2354a07644c985a846d10203b42b760574a212ea5c7dbb
Enrichment time
2026-05-05T07:23:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.