A public Metasploit module makes Paperclip AI immediately testable, and that changes the tempo more than the CVE itself. Once the exploit is in a framework, the jump from proof to active use gets much shorter, and the same release adds persistence and post-exploitation paths that extend the blast radius past the first web shell.
Rapid7’s release adds an unauthenticated exploit for CVE-2026-41679, which affects network-accessible Paperclip instances running in authenticated mode with default configuration. It also adds an NTLM relay-to-self local privilege escalation, a VS Code extension persistence module, and MCP server integration that lets AI tools assist inside msfconsole.
The practical risk is not just initial access. It is the speed with which an operator can move from exposed app to durable foothold and then into higher privileges using the same framework session.