Metasploit Wrap-Up 03/27/2026
2026-03-28T07:23:44Z•bd24341c0e07829b59480224f42340052fbd21d8c12cbef70319e3746dea86f9
BPFdoorCVE-2026-23767CVE-2026-3055CVSS 9.3CitrixESC/POSIoTNTLM relayingNetScalerRed MenshenRubySMBSAML IDPSMBcellular modulesmetasploitout-of-bounds readprinterstelecom compromisetelecommunicationsvulnerability-management
What happened
Collection of Rapid7 posts (late March 2026) covering multiple security developments: Metasploit updates improving SMB NTLM relaying (broader client compatibility including RubySMB and smbclient) and three new modules, including an ESC/POS printer command injector exploiting CVE-2026-23767 and an Eclipse Che unauthenticated RCE exploit module. Rapid7 published an advisory on Citrix NetScaler ADC/Gateway out-of-bounds read CVE-2026-3055 (CVSS 9.3) affecting SAML IDP configurations that can allow unauthenticated remote information disclosure. Additional intelligence includes a long-form threat‑h
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- bd24341c0e07829b59480224f42340052fbd21d8c12cbef70319e3746dea86f9
- Enrichment time
- 2026-03-28T07:23:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.