Metasploit Wrap-Up 04/10/2026
2026-04-12T19:23:50Z•d66b7f3c79ebc1a01ccfd746fd593dfe3f866754bb16b6a8e19e93bfbb26ca47
CVE-2025-59718CVE-2025-59719CVE-2026-20127active-directoryadcscisco-sd-wanexploitfortigatefreescoutgravincident-responseldapmetasploitmsfvenomosticketrapid7rcevulnerabilitywindows-persistence
What happened
Rapid7 published multiple blog posts covering Metasploit Framework updates and incident-response findings. Metasploit received new modules (including AD/CS Web Enrollment certificate issuance, modules targeting osTicket, FreeScout and Grav CMS leading to RCE, and Windows persistence/LDAP/ADCS helpers) and an auxiliary exploit module for a Cisco Catalyst SD‑WAN Controller authentication bypass tied to CVE-2026-20127 (recently observed exploited in the wild). Rapid7’s IR team also documented exploitation of FortiGate SSO signature verification vulnerabilities (CVE-2025-59718; related coverage of
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- d66b7f3c79ebc1a01ccfd746fd593dfe3f866754bb16b6a8e19e93bfbb26ca47
- Enrichment time
- 2026-04-12T19:23:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.