Metasploit Drops 16 Modules, Five on CISA KEV
Rapid7 adds 16 Metasploit modules, 10 exploits, five targeting KEV-listed CVEs in Cisco, PaperCut, SonicWall, JetBrains, and Langflow.

Rapid7 published a September Metasploit wrap-up Thursday with sixteen new modules. Ten are exploit modules. Five target vulnerabilities on CISA’s Known Exploited Vulnerabilities catalog, covering flaws in Cisco Secure Firewall Management Center, PaperCut NG/MF, SonicWall SMA1000, JetBrains TeamCity, and Langflow.
When a CVE lands in Metasploit, exploitation steps are reproducible in a documented, widely available framework. The bar for who can run the attack drops. For anything still unpatched and KEV-listed, the urgency was already maximum; this just removes the tooling constraint for more actors.
Cisco FMC
Three separate threat clusters have been exploiting Cisco FMC flaws, including a Qilin ransomware group and a state-sponsored actor. We covered the breakdown when Cisco confirmed active exploitation and again when the three-cluster picture emerged. If FMC is unpatched in your environment, the Metasploit module is not the reason to patch; it is one more reason to document why you have not.
PaperCut NG/MF
CVE-2026-81578 and CVE-2026-82078 are both actively exploited. PaperCut shipped a new security maintenance release this week to replace the earlier emergency patches. That replaces everything; install it, do not layer on top of prior hotfixes.
SonicWall SMA1000
Ransomware operators have been targeting SMA1000 since at least early September. Our SonicWall SMA1000 coverage tracks the active exploitation. A Metasploit module broadens access to the attack for lower-skilled actors.
JetBrains TeamCity
CVE-2026-63077 hits all on-prem TeamCity versions. JetBrains confirmed a breach at its own Cadence subsidiary through this flaw. Patch and review logs for unexpected agent connections or job creations.
Langflow
Multiple Langflow RCE CVEs have cycled through the KEV catalog this year. The most recent exploitation wave involved credential theft targeting OpenAI and AWS keys. Any Langflow instance reachable from the internet without strict network controls is the highest-urgency item in this update.
The other eleven modules
The remaining eleven modules cover older findings, none of them KEV-listed as of Thursday. If your team has limited patch capacity, clear the five KEV entries above first. Rapid7’s full module listing covers the complete rundown.
- [ CRITICAL ]CVE-2026-81578PaperCut NG/MF Authentication Bypass
- [ CRITICAL ]CVE-2026-82078PaperCut NG/MF Unsafe Class-Loading RCE
- [ CRITICAL ]CVE-2026-63077JetBrains TeamCity On-Prem Unauthenticated RCE
Found this useful? Share it.


