The weekly Metasploit update adds five new modules targeting critical vulnerabilities: an authentication bypass for Cisco Catalyst SD-WAN Controller (CVE-2026-20182), a zip-slip RCE for the HUSTOJ online judge platform (CVE-2026-24479), an unauthenticated RCE for Barracuda Email Security Gateway via Excel eval injection (CVE-2023-7102), a CRLF injection auth bypass leading to root RCE in cPanel/WHM (CVE-2026-41940), and a post-exploitation module for extracting and cracking Tenable Security Center credential hashes. The release also includes six enhancements (RPC improvements, Kerberoast documentation updates, Rails 8 dependency prep) and four bug fixes including Windows msfdb installation issues.

4m read timeFrom rapid7.com
Post cover image
Table of contents
Another week, another authentication bypassNew module content (5)Enhancements and features (6)Bugs fixed (4)DocumentationGet it
3 Impressions