Metasploit Wrap-Up 03/20/2026
2026-03-21T07:23:44Z•403b416cd6d6ba0e80c80a81ab0c855c4d38084de7022d94ee6a45f69a5790cb
AVideo-EncoderFreePBXGainsightcloud-securitycnappcommand-injectionexploit-modulesinformation-disclosuremetasploitmicrosoft-teams-phishingrapid7social-engineeringthreat-landscapevulnerability-managementxss
What happened
This Rapid7 collection covers multiple security developments from March 2026: a Metasploit wrap-up adding two new exploit modules — an unauthenticated OS command injection against AVideo Encoder (CVE-2026-29058) and an authenticated command injection against FreePBX filestore (CVE-2025-64328); disclosure and remediation of Gainsight Assist vulnerabilities (CVE-2026-31381 information disclosure and CVE-2026-31382 reflected XSS) with vendor fixes deployed in March 2026; guidance on an uptick in Microsoft Teams phishing campaigns that impersonate IT support to get users to launch Quick Assist (en
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- 403b416cd6d6ba0e80c80a81ab0c855c4d38084de7022d94ee6a45f69a5790cb
- Enrichment time
- 2026-03-21T07:23:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.