Metasploit Wrap-Up 03/20/2026

2026-03-22T07:23:44Z958ee19744c9a56880739b194b1799b5b54f1c3b81593b6efd8f5bc4ca263ab5
AVideoFreePBXGainsightcommand-injectionexploit-moduleglobal-threat-landscapeinformation-disclosuremetasploitmicrosoft-teamsphishingreflected-xsssocial-engineeringvulnerability-management

What happened

Rapid7 published multiple security updates: Metasploit added two new exploit modules (unauthenticated OS command injection in AVideo Encoder getImage.php — CVE-2026-29058 — and an authenticated FreePBX filestore command injection — CVE-2025-64328). Rapid7 Labs disclosed and Gainsight patched an information disclosure and a reflected XSS in Gainsight Assist (CVE-2026-31381, CVE-2026-31382) with fixes deployed March 6–9, 2026. Rapid7 also warned of an increase in Microsoft Teams-based phishing where attackers impersonate IT to get victims to run Quick Assist for remote access. Their GlobalThreat

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
958ee19744c9a56880739b194b1799b5b54f1c3b81593b6efd8f5bc4ca263ab5
Enrichment time
2026-03-22T07:23:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.