This week's release features a 2x faster msfvenom bootup time and new modules, including exploits for the Cisco Catalyst SD-WAN Controller Authentication Bypass (CVE-2026-20127) and osTicket Arbitrary File Read (CVE-2026-22200). https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-04-10-2026/

Metasploit Wrap-Up 04/10/2026
Get the latest Metasploit Framework update, featuring an approximate two-times speedup in msfvenom's bootup time. This release introduces new modules targeting critical vulnerabilities, including an authentication bypass zero-day in Cisco Catalyst SD-WAN Controller (CVE-2026-20127) and an authenticated file read in osTicket (CVE-2026-22200). Key improvements also include a new AD/CS Web Enrollment service module, enhancements to Windows service-for-user persistence, and better reporting for LDAP/ADCS-related services.