Metasploit 2026: External Recon and Web Exploitation
An adversary is using recently released Metasploit scanner and exploit modules to fingerprint organization SCADA infrastructure or exploit unauthenticated vulnerabilities in public-facing web applications.
Based on research by Rapid7 2026-09-28 9 steps · 3 queries T1190
Brief
Why Now
The Rapid7 "Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!" (https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-payloads-exploits-scanners) highlights new scanner and exploit modules targeting unauthenticated web vulnerabilities and industrial control systems. These public releases lower the barrier for opportunistic actors to scan and exploit organizational infrastructure.
How the Hunt Flows
The first step queries the vulnerability inventory to list every host matching specific CVEs like CVE-2026-3576 and CVE-2026-0265. This scoping phase narrows the focus to assets where these Metasploit modules are effective. In the next phase, the hunt runs parallel queries across HTTP and network surfaces. One query monitors for suspicious URL paths associated with Concrete CMS and AJAX proxies, looking specifically for file-based protocols in parameters. Simultaneously, another query checks for rare network connections on port 4840 to identify unauthorized OPC-UA binary transport traffic. A triage agent then evaluates the collected telemetry against the vulnerability findings. It confirms whether the observed traffic patterns indicate a successful intrusion by linking the exploit attempts to hosts known to be vulnerable. Finally, the hunt routes confirmed malicious activity to an automated isolation task. This halts the adversary's progress while an analyst manually reviews the full payload content and status codes to finalize the incident response.
Blind Spots
This hunt relies on managed endpoint and network telemetry. It cannot see scanning attempts originating from or targeting unmanaged devices that do not report to the central logs. Furthermore, specific exploit patterns like the SPIP RCE target HTTP headers that are not always normalized in the current telemetry surface, creating a gap in coverage for those specific techniques.
In this series
Steps
-
Identify vulnerable assets
Query · scopingLocate assets currently known to be vulnerable to the Metasploit modules' target CVEs and retrieve their hostnames for subsequent filtering.
reads hb_vulnerability_findingsqlSELECT d.hostname, f.cve_uid, f.severity, f.title, f.affected_package_name, f.affected_package_version FROM hb_vulnerability_finding AS f JOIN hb_devices AS d ON f.device_uid = d.device_uid WHERE instr(',' || '{{metasploit_cves}}' || ',', ',' || f.cve_uid || ',') > 0 AND f.status != 'suppressed'What a hit looks like. Hosts with high-severity findings matching the CVE list. Silence means no known exposures exist in the inventory.
-
Web exploitation attempts
Query · detection candidateIdentify HTTP requests targeting AJAX proxies or vulnerable controllers with LFI patterns to detect active exploitation.
reads hb_http_activitysqlSELECT device_hostname, src_endpoint_ip, url_path, url_query, status_code, user_agent, time FROM hb_http_activity WHERE (instr(',' || '{{suspicious_paths}}' || ',', ',' || LOWER(url_path) || ',') > 0 OR LOWER(url_query) LIKE '%file://%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')What a hit looks like. Requests to ulap.php or Concrete CMS paths, especially with file:// schemes in parameters. Silence means no probes were captured.
-
SCADA protocol fingerprinting
Query · baselineDetect rare connections to OPC-UA binary transport ports on scoped hosts to identify unauthorized SCADA scanning.
reads hb_network_connectionsqlSELECT device_hostname, dst_endpoint_ip, dst_endpoint_port, COUNT(DISTINCT src_endpoint_ip) AS unique_sources, MIN(time) AS first_seen FROM hb_network_connection WHERE dst_endpoint_port = 4840 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, dst_endpoint_ip, dst_endpoint_port HAVING unique_sources < 5What a hit looks like. Connections to port 4840 from unexpected sources. Silence means no OPC-UA scanning was observed.
-
Triage vulnerabilities and traffic
Agent triageEvaluate if the observed traffic on vulnerable hosts indicates successful exploitation.
-
Evaluate compromise
DecisionRoute to remediation if exploitation is confirmed by the triage agent.
-
Isolate affected host
Response actionHalt further exploitation on confirmed compromised hosts by isolating them from the network.
-
Analyst manual review
Analyst taskVerify the agent's findings and assess the payload content in HTTP queries manually.
-
Close out hunt
Analyst taskFinalize findings and record recommendations for detection engineering and vulnerability management.
Coverage
Scenario coverage
| Stage | Covered | How, or why not |
|---|---|---|
| Protocol and Application Fingerprinting T1190 |
Yes | identify-vulnerable-assets, scada-fingerprinting-traffic |
| Exploitation of Web Vulnerabilities T1190 |
Yes | web-exploitation-attempts, triage-signals |
| Authenticated Execution and Payloads T1059.001 |
Out of scope | Belongs to another part of the 'Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!' series. |
| Lateral Movement via SMB and WinRM T1021.002 |
Out of scope | Belongs to another part of the 'Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!' series. |
| Persistence via CreateProcess T1059.001 |
Out of scope | Belongs to another part of the 'Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!' series. |
Blind spots
- Needs hb_http_activity and hb_network_connection from perimeter devices. A scanning host not enrolled in telemetry will not appear in network or HTTP logs. It would answer Are there scanning attempts from unmanaged internal devices?.
- Needs hb_http_activity with header visibility. The SPIP RCE targets specific HTTP headers which are not fully normalized in the current surface, leading to potential misses. It would answer Was the SPIP X-Spip-Filtre header used in the attack?.
Parameters & data
Parameters
| Parameter | Type | Default | What it is |
|---|---|---|---|
lookback_days | number | 14 | Days of history to examine. |
metasploit_cves | list[string] | CVE-2026-0265, CVE-2026-16232, CVE-2026-3576, CVE-2026-6826, CVE-2026-9082, CVE-2026-59774 | CVEs targeted by the new Metasploit modules. |
scope_hosts | list[host] | — | List of hostnames from the scoping step to focus the hunt on; leave empty for fleet-wide. |
suspicious_paths | list[path] | /ulap.php pulp-ajax-proxy, /ccm/system/dialogs/file/usage/, /ccm/system/dialogs/file/usage | Sensitive URL paths associated with the reported vulnerabilities. |
Telemetry
| Source | Category | Telemetry |
|---|---|---|
| Endpoint telemetry (hb_ surfaces) | endpoint | endpoint |
| Network telemetry | network | network |
| Web server / proxy logs | siem | network |
Source
---
analysis: This hunt correlates known vulnerability inventory with behavioral traffic
patterns like SCADA protocol usage, which is often not monitored by standard security
rules.
blind_spots:
- id: incomplete-telemetry
question: Are there scanning attempts from unmanaged internal devices?
requires: hb_http_activity and hb_network_connection from perimeter devices
risk: A scanning host not enrolled in telemetry will not appear in network or HTTP
logs.
stage: vulnerability-scanning-and-reconnaissance
- id: http-header-blindness
question: Was the SPIP X-Spip-Filtre header used in the attack?
requires: hb_http_activity with header visibility
risk: The SPIP RCE targets specific HTTP headers which are not fully normalized
in the current surface, leading to potential misses.
stage: exploit-public-facing-web-applications
coverage:
- stage: vulnerability-scanning-and-reconnaissance
status: covered
steps:
- identify-vulnerable-assets
- scada-fingerprinting-traffic
- stage: exploit-public-facing-web-applications
status: covered
steps:
- web-exploitation-attempts
- triage-signals
- reason: 'Belongs to another part of the ''Metasploit Wrap Up: Payloads and Exploits,
and Scanners, Oh my!'' series.'
stage: remote-command-execution-and-payloads
status: out_of_scope
- reason: 'Belongs to another part of the ''Metasploit Wrap Up: Payloads and Exploits,
and Scanners, Oh my!'' series.'
stage: lateral-movement-smb-winrm
status: out_of_scope
- reason: 'Belongs to another part of the ''Metasploit Wrap Up: Payloads and Exploits,
and Scanners, Oh my!'' series.'
stage: persistence-via-process-creation
status: out_of_scope
guardrails:
claims: no_unsupported
evidence: citation_required
missing_data: not_benign
telemetry: untrusted
hunt:
applicability: campaign-specific
handoff: promote-to-detection
justification: Public Metasploit module releases lower the bar for opportunistic
attackers. Proactively hunting for these artifacts ensures the estate is protected
against known exploit code.
methodology: model-assisted
trigger: intel-report
hypothesis: An adversary is using recently released Metasploit scanner and exploit
modules to fingerprint organization SCADA infrastructure or exploit unauthenticated
vulnerabilities in public-facing web applications.
labels:
- hunt
- attack.t1190
name: 'Metasploit 2026: External Recon and Web Exploitation'
parameters:
lookback_days:
default: '14'
description: Days of history to examine.
type: number
metasploit_cves:
default:
- CVE-2026-0265
- CVE-2026-16232
- CVE-2026-3576
- CVE-2026-6826
- CVE-2026-9082
- CVE-2026-59774
description: CVEs targeted by the new Metasploit modules.
from:
kind: article
observed: '2026-08-28'
ref: metasploit-wrap-up-aug-2026
type: list[string]
scope_hosts:
default: []
description: List of hostnames from the scoping step to focus the hunt on; leave
empty for fleet-wide.
type: list[host]
suspicious_paths:
default:
- /ulap.php pulp-ajax-proxy
- /ccm/system/dialogs/file/usage/
- /ccm/system/dialogs/file/usage
description: Sensitive URL paths associated with the reported vulnerabilities.
from:
kind: article
observed: '2026-08-28'
ref: metasploit-wrap-up-aug-2026
type: list[path]
provenance:
authors:
- name: Huntbase hunt generation
org: huntbase.io
generated:
by: huntbase-hunt-generation
from: https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-payloads-exploits-scanners
gates:
- dry-run
- lint
model: hb_google/gemini-3-flash-preview
rationale: Prioritize web servers hosting WordPress or Concrete CMS, and SCADA control
systems. If no vulnerability findings are current, expand the HTTP query to all
external-facing assets.
references:
- name: 'Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!'
url: https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-payloads-exploits-scanners
related:
- hunt: metasploit-payload-execution-and-persistence
reason: This hunt focuses on initial reconnaissance and unauthenticated exploitation;
the post-compromise stages are handled separately.
relation: out-of-scope-alternative
scenario:
stages:
- name: Protocol and Application Fingerprinting
observables:
- opc.tcp://
- /ccm/system/dialogs/file/usage/
- CVE-2026-0265
- CVE-2026-16232
- CVE-2026-6826
slug: vulnerability-scanning-and-reconnaissance
tactic: initial-access
techniques:
- T1190
- name: Exploitation of Web Vulnerabilities
observables:
- ulap.php
- file://localhost/etc/passwd
- X-Spip-Filtre
- CVE-2026-3576
- CVE-2026-59774
- CVE-2026-9082
- CVE-2026-66066
slug: exploit-public-facing-web-applications
tactic: initial-access
techniques:
- T1190
- name: Authenticated Execution and Payloads
observables:
- PSRP-backed PowerShell session
- MIPS64 exec payload
- CVE-2026-19681
- CVE-2026-21820
- CVE-2026-56274
slug: remote-command-execution-and-payloads
tactic: execution
techniques:
- T1059.001
- name: Lateral Movement via SMB and WinRM
observables:
- windows/smb/psexec aarch64
- winrm_login with SessionType PSRP
slug: lateral-movement-smb-winrm
tactic: lateral-movement
techniques:
- T1021.002
- name: Persistence via CreateProcess
observables:
- Metasploit persistence modules using create_process instead of cmd_exec
slug: persistence-via-process-creation
tactic: persistence
techniques:
- T1059.001
summary: This Metasploit update details a range of exploit and scanner modules targeting
vulnerabilities in web platforms (Forgejo, WordPress, Drupal, SPIP), networking
hardware (PAN-OS, Check Point), and SCADA protocols. The framework has been enhanced
to support remote execution via PSRP-backed PowerShell sessions, cross-platform
SMB movement on aarch64, and improved persistence through native process creation.
series:
index: 1
slug: metasploit-wrap-up-payloads-and-exploits-and-scanners-oh-my
title: 'Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!'
total: 2
severity: high
targets:
analyst:
name: Tier-2 analyst
role: analyst
endpoint:
category: endpoint
name: Endpoint telemetry (hb_ surfaces)
telemetry:
- endpoint
hunter:
agent: true
name: Hunt agent
network:
category: network
name: Network telemetry
telemetry:
- network
web:
category: siem
name: Web server / proxy logs
telemetry:
- network
tlp: clear
type: investigation
---
# Metasploit 2026: External Recon and Web Exploitation
This hunt targets the initial access and reconnaissance phases following the release of new Metasploit modules for CVE-2026-3576, CVE-2026-0265, and others. It first identifies hosts known to be vulnerable to these specific CVEs, then fanned out to investigate HTTP and network telemetry for active probing. An agent evaluates whether observed traffic patterns, such as LFI attempts or rare SCADA protocol connections, indicate a successful intrusion.
## identify-vulnerable-assets
<!-- Identify vulnerable assets -->
Locate assets currently known to be vulnerable to the Metasploit modules' target CVEs and retrieve their hostnames for subsequent filtering.
```sqlite target=endpoint role=scoping params=(metasploit_cves=metasploit_cves)
~~~yaml
expected: Hosts with high-severity findings matching the CVE list. Silence means no
known exposures exist in the inventory.
reads:
- device_uid
- cve_uid
- severity
- title
- affected_package_name
- affected_package_version
silence: not_evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT d.hostname, f.cve_uid, f.severity, f.title, f.affected_package_name, f.affected_package_version FROM hb_vulnerability_finding AS f JOIN hb_devices AS d ON f.device_uid = d.device_uid WHERE instr(',' || '{{metasploit_cves}}' || ',', ',' || f.cve_uid || ',') > 0 AND f.status != 'suppressed'
```
## corroborate-activity
<!-- Corroborate with traffic logs -->
parallel:
- → web-exploitation-attempts
- → scada-fingerprinting-traffic
join: → triage-signals
## web-exploitation-attempts
<!-- Web exploitation attempts -->
Identify HTTP requests targeting AJAX proxies or vulnerable controllers with LFI patterns to detect active exploitation.
```sqlite target=web role=detection-candidate params=(suspicious_paths=suspicious_paths, scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: Requests to ulap.php or Concrete CMS paths, especially with file:// schemes
in parameters. Silence means no probes were captured.
reads:
- device_hostname
- src_endpoint_ip
- url_path
- url_query
- status_code
- user_agent
- time
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, src_endpoint_ip, url_path, url_query, status_code, user_agent, time FROM hb_http_activity WHERE (instr(',' || '{{suspicious_paths}}' || ',', ',' || LOWER(url_path) || ',') > 0 OR LOWER(url_query) LIKE '%file://%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```
## scada-fingerprinting-traffic
<!-- SCADA protocol fingerprinting -->
Detect rare connections to OPC-UA binary transport ports on scoped hosts to identify unauthorized SCADA scanning.
```sqlite target=network role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
baseline:
compare: first_seen
window: '{{lookback_days}}d'
expected: Connections to port 4840 from unexpected sources. Silence means no OPC-UA
scanning was observed.
prevalence:
by: device_hostname
key:
- dst_endpoint_ip
rare_below: 5
reads:
- device_hostname
- dst_endpoint_ip
- dst_endpoint_port
- src_endpoint_ip
- time
silence: not_evidence_of_absence
source: hb_network_connection
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, dst_endpoint_ip, dst_endpoint_port, COUNT(DISTINCT src_endpoint_ip) AS unique_sources, MIN(time) AS first_seen FROM hb_network_connection WHERE dst_endpoint_port = 4840 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, dst_endpoint_ip, dst_endpoint_port HAVING unique_sources < 5
```
## triage-signals
<!-- Triage vulnerabilities and traffic -->
```agent target=hunter
cite: required
context:
- identify-vulnerable-assets
- web-exploitation-attempts
- scada-fingerprinting-traffic
max_iterations: 3
objective: Determine if the HTTP or network traffic suggests successful exploitation
of the identified vulnerabilities.
success_criteria: A verdict citing malicious traffic to a host with a matching CVE
finding.
tools:
- endpoint
- network
- web
```
## evaluate-compromise
<!-- Evaluate compromise -->
if~: "The triage verdict is malicious for at least one host" (confidence: high, judge=hunter)
then: → isolate-endpoint
indeterminate: → analyst-manual-review
unavailable: → analyst-manual-review (blind_spot: incomplete-telemetry)
else: → close-out
## isolate-endpoint
<!-- Isolate affected host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host and initiate the incident response process for initial access.
```
→ analyst-manual-review
## analyst-manual-review
<!-- Analyst manual review -->
```manual target=analyst
Review the full url_query for LFI patterns and verify if the status_code was 200 on vulnerable hosts.
```
→ close-out
## close-out
<!-- Close out hunt -->
```manual target=analyst
Report any missing patches identified in the scoping step and tuning recommendations for the HTTP detection candidate.
```
→ end
Run it
Take this hunt into your environment.
Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.
Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.