Metasploit Wrap-Up 04/10/2026

2026-04-11T19:23:48Zacb93bea6008630b44246f4b48b717e3c47007a09aa344fcc6191da63f712d73
active-directoryadcsai-vulnerability-discoveryauthentication-bypasscisco-sd-wancve-2025-59718cve-2025-59719cve-2026-20127fortigatefreescoutgrav-cmsincident-responsemdr-microsoftmetasploitmsfvenomosTicketpersistenceproject-glasswingrapid7-productsrceweb-enrollment

What happened

Rapid7 weekly roundup and product updates covering new Metasploit Framework modules and improvements, Active Directory Certificate Services tooling, and exploitation incident findings. Metasploit additions include an AD/CS authenticated web enrollment module, modules for Cisco Catalyst SD‑WAN Controller authentication bypass (linked to CVE-2026-20127 and observed exploited in the wild), new RCE modules targeting FreeScout, Grav CMS, and osTicket, Windows persistence enhancements, and msfvenom startup speed improvements. Rapid7 Incident Response details exploitation of FortiGate SSO signature‑b

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
acb93bea6008630b44246f4b48b717e3c47007a09aa344fcc6191da63f712d73
Enrichment time
2026-04-11T19:23:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Metasploit Wrap-Up 04/10/2026 · Baitaphish