Metasploit Wrap-Up 02/27/2026

2026-03-04T22:24:30Zc54b1d5b1880746ee49807e0232ad7ca650347bbda2a077026016046e324d667
CVE-2024-37032CVE-2025-62521CVE-2025-7441CVE-2026-1731CVE-2026-20127CVE-2026-21858CVE-2026-2329arbitrary-file-readarm64command-injectionevasionexploit-modulesexploited-in-the-wildmetasploitnetworkingpath-traversalrapid7rc4scanning-toolsvoipvulnerabilityweb-app

What happened

Rapid7 published multiple posts (Metasploit wrap-ups and ETR advisories) describing new Metasploit modules, active exploitation, and published CVEs. Key Metasploit additions include an Ollama path-traversal → RCE chain (CVE-2024-37032), Grandstream GXP1600 stack overflow with credential harvesting/SIP interception post‑modules (CVE-2026-2329), a BeyondTrust PRA/RS module updated for a command injection (CVE-2026-1731), and several other exploit and auxiliary modules (n8n Ni8mare arbitrary file read CVE-2026-21858; StoryChief WordPress CVE-2025-7441; ChurchCRM installation RCE CVE-2025-62521).E

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
c54b1d5b1880746ee49807e0232ad7ca650347bbda2a077026016046e324d667
Enrichment time
2026-03-04T22:24:30Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.