Metasploit Wrap-Up 03/20/2026

2026-03-21T07:23:44Z403b416cd6d6ba0e80c80a81ab0c855c4d38084de7022d94ee6a45f69a5790cb
AVideo-EncoderFreePBXGainsightcloud-securitycnappcommand-injectionexploit-modulesinformation-disclosuremetasploitmicrosoft-teams-phishingrapid7social-engineeringthreat-landscapevulnerability-managementxss

What happened

This Rapid7 collection covers multiple security developments from March 2026: a Metasploit wrap-up adding two new exploit modules — an unauthenticated OS command injection against AVideo Encoder (CVE-2026-29058) and an authenticated command injection against FreePBX filestore (CVE-2025-64328); disclosure and remediation of Gainsight Assist vulnerabilities (CVE-2026-31381 information disclosure and CVE-2026-31382 reflected XSS) with vendor fixes deployed in March 2026; guidance on an uptick in Microsoft Teams phishing campaigns that impersonate IT support to get users to launch Quick Assist (en

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
403b416cd6d6ba0e80c80a81ab0c855c4d38084de7022d94ee6a45f69a5790cb
Enrichment time
2026-03-21T07:23:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Metasploit Wrap-Up 03/20/2026 · Baitaphish