Metasploit Wrap-Up 03/13/2026

2026-03-14T19:23:46Z71ecf15c737951012ee5fe18bb3daeb7b2c7bd05585e921fe23659f18111a595
data-exposureelevation-of-privilegeevading-detectionexploit-moduleexposed-data-discoveryiran-linked-activityleakixmetasploitmetasploit-pro-5.0patch-tuesdaypayload-packerrcespip-saisiessql-serverthreat-detection

What happened

Rapid7 published multiple blog updates including a Metasploit Framework release that adds three new modules: an auxiliary LeakIX search (exposed services and leaked data discovery), a Linux x64 RC4 encrypted payload packer for evasion, and an unauthenticated RCE exploit module for SPIP Saisies (CVE-2025-71243). They also announced Metasploit Pro 5.0.0 with an updated UI and SSO support. Related Rapid7 posts include Patch Tuesday coverage noting CVE-2026-21262 (SQL Server elevation-of-privilege, CVSS 8.8) and broader detection/response guidance for Iran-linked activity and data exposure risk.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
71ecf15c737951012ee5fe18bb3daeb7b2c7bd05585e921fe23659f18111a595
Enrichment time
2026-03-14T19:23:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.