Metasploit Wrap-Up 03/13/2026

2026-03-15T19:23:45Z21e16f63230869d2e6285cf7cba2e3ed2124b9009bc2ac756b09eacb255e0a42
cve-2025-71243cve-2026-21262evasioniran-linked-activityleakixmetasploitmetasploit-pro-5.0.0patch-tuesdaypodcastrc4-packerrcespipsql-serverthreat-detection

What happened

Rapid7 published several March 2026 updates: Metasploit Framework added three new modules — LeakIX-powered discovery (auxiliary/gather/leakix_search), a Linux x64 RC4 payload packer (evasion/linux/x64/rc4_packer), and an unauthenticated RCE exploit for SPIP Saisies (CVE-2025-71243). Metasploit Pro 5.0.0 was released with a redesigned UI, SSO support, and workflow improvements. Separately, Microsoft’s March 2026 Patch Tuesday fixed 77 vulnerabilities including a publicly disclosed SQL Server elevation-of-privilege (CVE-2026-21262, CVSSv3 8.8) that can allow privilege escalation to sysadmin over

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
21e16f63230869d2e6285cf7cba2e3ed2124b9009bc2ac756b09eacb255e0a42
Enrichment time
2026-03-15T19:23:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.