Metasploit Wrap-Up 05/01/2026

2026-05-04T19:23:50Zf2c0a190ae2a1f92509fb7d4f477ae384a92f47178ffd4e727f29110a3643bfe
CVE-2024-46987CVE-2026-31431CVE-2026-41940CVSS 9.8Camaleon CMSCopy FailMCP serverModel Context ProtocolWHMauthentication bypasscPanelcheck-method visibilitydirectory traversalexploit availablelegacy SMBlinux local privilege escalationmetasploitpublic PoCrapid7security updateunauthenticated remote

What happened

Rapid7 blog roundup (late Apr–May 2026): Metasploit added a read-only MCP (Model Context Protocol) server to expose framework data to AI agents and shipped new modules and UX improvements (check-method reasoning, legacy SMB fixes). Metasploit published a local exploit for the recently disclosed Linux Kernel logic flaw “Copy Fail” (CVE-2026-31431) — public PoC exists and Metasploit’s exploit targets AMD64/AARCH64 by replacing the ‘su’ binary in the page cache to execute payloads. Rapid7 also covered a critical cPanel & WHM authentication bypass (CVE-2026-41940, CVSS 9.8) that allows unauth’d, R

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
f2c0a190ae2a1f92509fb7d4f477ae384a92f47178ffd4e727f29110a3643bfe
Enrichment time
2026-05-04T19:23:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.