Metasploit Wrap-Up 02/27/2026
2026-03-04T22:24:30Z•c54b1d5b1880746ee49807e0232ad7ca650347bbda2a077026016046e324d667
CVE-2024-37032CVE-2025-62521CVE-2025-7441CVE-2026-1731CVE-2026-20127CVE-2026-21858CVE-2026-2329arbitrary-file-readarm64command-injectionevasionexploit-modulesexploited-in-the-wildmetasploitnetworkingpath-traversalrapid7rc4scanning-toolsvoipvulnerabilityweb-app
What happened
Rapid7 published multiple posts (Metasploit wrap-ups and ETR advisories) describing new Metasploit modules, active exploitation, and published CVEs. Key Metasploit additions include an Ollama path-traversal → RCE chain (CVE-2024-37032), Grandstream GXP1600 stack overflow with credential harvesting/SIP interception post‑modules (CVE-2026-2329), a BeyondTrust PRA/RS module updated for a command injection (CVE-2026-1731), and several other exploit and auxiliary modules (n8n Ni8mare arbitrary file read CVE-2026-21858; StoryChief WordPress CVE-2025-7441; ChurchCRM installation RCE CVE-2025-62521).E
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- c54b1d5b1880746ee49807e0232ad7ca650347bbda2a077026016046e324d667
- Enrichment time
- 2026-03-04T22:24:30Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.