Weekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and More
Rapid7, Friday, June 19th, 2026
Rapid7's weekly Metasploit update adds new modules including an MCP server integration and a Paperclip AI RCE chain.
Rapid7's weekly Metasploit update introduces five new modules and seven enhancements. Highlights include an unauthenticated RCE chain for Paperclip AI and a Windows privilege escalation technique using NTLM relay attacks.
The release adds a Model Context Protocol server plugin that lets AI tools assist operators within msfconsole without restarts. Additional improvements cover search functionality, module check details, and Redis output formatting, along with four bug fixes.