Vulnerability threat dossier

CVE-2026-20929

Vendor unknownProduct mapping pending

Metadata pending authoritative retrieval.

VTP deterministic threat2.6of 100 · CVSS excluded

VTP analyst assessment

Technical impact for CVE-2026-20929 remains unavailable

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence92%
Public exploitation · VTP factUNKNOWN

Assessment

No authoritative vulnerability metadata or exploit evidence is available for CVE-2026-20929 in this record. Rapid7 published a Metasploit roundup, but the supplied excerpt does not establish the affected product, mechanism, or exploitation status for this CVE.

Why it matters

  • Defenders cannot map this CVE to systems or select a remediation without authoritative product and version details.

Evidence

3 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

The affected product, vulnerability mechanism, severity, remediation, and exploitation status are unknown.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

Obtain the authoritative CVE record or vendor advisory before taking product-specific action.

AI baseline history (1)
  1. BASELINE ASSESSED
    Technical impact for CVE-2026-20929 remains unavailablegpt-5.6-terra · low
Technical severityUNKNOWNCVSS unknown · technical context
Public exploitationUNKNOWNGlobal public evidence
Exploit maturityNONE KNOWNReliability not implied
EPSS0.0386th percentile · prediction
Evidence confidence0%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    EPSS is 0.03; this is predictive context, not exploitation evidence.

  2. 02

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

RESEARCH PUBLICATIONNew technical research
RESEARCH PUBLICATIONNew technical research
03

Claim provenance

Evidence and source independence

2publications detected
2underlying evidence chains

1 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

04

Event history

Threat timeline

  1. 14:3825 Sept
    RESEARCH PUBLICATION

    New technical research

    Rapid7 Research published evidence linked to CVE-2026-20929.

  2. 13:3511 Sept
    RESEARCH PUBLICATION

    New technical research

    Rapid7 Research published evidence linked to CVE-2026-20929.

05

Original publications

Source record

Metasploit Wrap Up: Belgian Waffles, Chocolates, and…Modules-Frites?

CVE-2026-18729CVE-2026-20929CVE-2026-85706
Separate evidence group
Original

Metasploit Wrap Up: This One Goes to Sixteen!

This One Goes to Sixteen! Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit modules, and not to be outdone, we even have a Metasploit scanner to watch the watchers! New module content (16) Elasticsearch ingest-attachment Apache Tika XFA XXE Local File Read Authors: Bourbon Offensive Security Services and Jean-Marie Bourbon Type: Auxiliary Pull request: #21739 contributed by kmkz Path: scanner/http/elasticsearch_tika_xfa_xxe CVE reference: CVE-2025-66516 Description: Adds an auxiliary scanner module for CVE-2025-54988/CVE-2025-66516. The module validates an XML External Entity (XXE) vulnerability in Apache Tika's XFA parser exposed through the Elasticsearch attachment ingest processor. SPIP Unauthenticated Blind SQLi via Date Field Escaping Bypass Authors: Benoit Hua, Franck Chevalier, Julien Voisin, and ka3n1x Type: Auxiliary Pull request: #21791 contributed by jvoisin Path: scanner/http/spip_annee_sqli Description: Adds modules/auxiliary/scanner/http/spip_annee_sqli.rb which exploits a blind SQL injection in SPIP's date column escaping logic. Metasploit Payload Handler Detection (TCP/UDP/HTTP/HTTPS) Author: h00die Type: Auxiliary Pull request: #21551 contributed by h00die Path: scanner/msf/handler_detect Description: Adds a scanner module to enumerate ports on a host and determine if they're a Metasploit Reverse Handler or not, and if they are, what kind of shell they were going to land. ESC8 Relay: SMB to HTTP(S) via Kerberos Author: Pushpender Rathore Type: Auxiliary Pull request: #21709 contributed by Pushpenderrathore Path: server/relay/esc8_kerberos CVE reference: CVE-2026-20929 Description: This introduces native Kerberos authentication relay capabilities to the framework's relay stack. It includes a new auxiliary module (esc8_kerberos) that exploits CVE-2026-20929 by targeting AD CS Web Enrollment (ESC8). The module captures an SMB2 AP-REQ from a coerced client and seamlessly replays the authentication to the target certificate server over HTTP. This chain ultimately allows an attacker to issue a certificate for the coerced victim and obtain a valid Kerberos TGT without requiring their credentials. Linux x64 Sandbox Environment Gate Author: Massimo Bertocchi Type: Evasion Pull request: #21642 contributed by litemars Path: linux/x64/sandbox_gate Description: Adds a Linux x64 sandbox‑evasion module that performs lightweight runtime environment checks and aborts execution when a likely sandbox or VM is detected. Cisco Secure Firewall Management Center Authentication Bypass RCE Authors: Arian Eidizadeh, Brandon Sakai, and Cale Black Type: Exploit Pull request: #21796 contributed by CyberAuth Path: linux/http/cisco_fmc_auth_bypass_rce CVE reference: CVE-2026-20079 Description: Adds a native Metasploit exploit module for CVE-2026-20079, an unauthenticated authentication bypass in Cisco Secure Firewall Management Center (FMC). SonicWall SMA1000 WorkPlace SSRF to Root Remote Code Execution Authors: Adam Babis, William Perry, and sfewer-r7 Type: Exploit Pull request: #21883 contributed by sfewer-r7 Path: linux/http/sonicwall_sma1000_couchdb_rce CVE reference: CVE-2026-83549 Description: This adds an exploit module for the recent SonicWall SMA1000 zero-day exploit chain that was disclosed in the first week of September as being exploited in-the-wild. CVE-2026-83548 is an SSRF used to bypass auth. SMA1000-9427 is an RCE with low privileges via CouchDB read/write primitives. CVE-2026-83549 is a command injection in cmsSnmpTrap.sh for RCE with root privs. The patched version 12.5.0-02952 has been verified to successfully remediate this exploit chain. JetBrains TeamCity Agent Polling Unauthenticated Remote Code Execution Authors: Antoni Tremblay and sfewer-r7 Type: Exploit Pull request: #21775 contributed by sfewer-r7 Path: multi/http/jetbrains_teamcity_rce_cve_2026_63077 CVE reference: CVE-2026-

CVE-2025-54988CVE-2025-66516CVE-2026-19295CVE-2026-20079CVE-2026-20929CVE-2026-23744CVE-2026-48558CVE-2026-63077CVE-2026-75604CVE-2026-81578CVE-2026-82078CVE-2026-83548CVE-2026-83549
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score2.6vtp-threat-v1-public
Public exploitation0 / 30
EPSS prediction0.58 / 20
Exploit availability0 / 15
Source independence0 / 15
Intelligence recency0 / 10
Threat acceleration2 / 10
CVSS technical severityExcluded
CVSS
Unknown · UNKNOWN
Vector
Unknown
CWE
Unknown
CPE records
0
Deterministic history records
14
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.