Metasploit Wrap-Up 05/08/2026
2026-05-10T07:23:42Z•d09531f7e41fbd41f8461fce6ef3dbdf5fb7d1266162276f6b2fea8aca308c2c
CTEMCVE-1999-0497CVE-2026-0300DWAgentOpenAI-trusted-accessRATbuffer-overflowchaos-ransomwarecopy-faildetection-as-codedetection-engineeringexploit-modulesftp-anonymousmetasploitmuddywaterpalo-alto-pan-osransomware-false-flagshiro_rememberme
What happened
This Rapid7 collection (May 6–8, 2026) covers multiple security topics: Metasploit updates (payload fixes for linux/x64/exec and linux/armle/exec, expanded Copy Fail exploit payload support, improved exploit/multi/http/shiro_rememberme_v124_deserialize options, and a new/updated anonymous FTP scanner module that references CVE-1999-0497 and stores proof-of-exploit); a high-severity Palo Alto PAN-OS User‑ID Authentication Portal buffer overflow (CVE-2026-0300) with a vendor-confirmed in-the-wild exploit and CVSSv4 9.3; threat reporting on a MuddyWater (Seedworm) campaign that used social-engine
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- d09531f7e41fbd41f8461fce6ef3dbdf5fb7d1266162276f6b2fea8aca308c2c
- Enrichment time
- 2026-05-10T07:23:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.