Metasploit Wrap-Up 03/20/2026
2026-03-22T07:23:44Z•958ee19744c9a56880739b194b1799b5b54f1c3b81593b6efd8f5bc4ca263ab5
AVideoFreePBXGainsightcommand-injectionexploit-moduleglobal-threat-landscapeinformation-disclosuremetasploitmicrosoft-teamsphishingreflected-xsssocial-engineeringvulnerability-management
What happened
Rapid7 published multiple security updates: Metasploit added two new exploit modules (unauthenticated OS command injection in AVideo Encoder getImage.php — CVE-2026-29058 — and an authenticated FreePBX filestore command injection — CVE-2025-64328). Rapid7 Labs disclosed and Gainsight patched an information disclosure and a reflected XSS in Gainsight Assist (CVE-2026-31381, CVE-2026-31382) with fixes deployed March 6–9, 2026. Rapid7 also warned of an increase in Microsoft Teams-based phishing where attackers impersonate IT to get victims to run Quick Assist for remote access. Their GlobalThreat
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- 958ee19744c9a56880739b194b1799b5b54f1c3b81593b6efd8f5bc4ca263ab5
- Enrichment time
- 2026-03-22T07:23:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.