Metasploit Wrap-Up 03/13/2026
2026-03-15T07:23:46Z•ce87f68ee57076c648e69d174cbab55245811a80aff66b59e9b268e72e1ed360
LeakIXSPIPdata-exposuredetection-coverageelevation-of-privilegeevasionexploit-moduleiran-linked-activityleakix_searchmetasploitmetasploit-propatch-tuesdaypayload-packerpodcastpublic-disclosurerc4remote-code-executionsql-server
What happened
Rapid7 published a Metasploit Framework update (03/13/2026) that adds three new modules: an auxiliary LeakIX search module for discovering exposed services and leaked data, a Linux x64 RC4 payload packer for evasion, and an unauthenticated remote code execution (RCE) exploit for SPIP Saisies (CVE-2025-71243). They also announced Metasploit Pro 5.0.0 with UI improvements and SSO, and published posts on Iran‑linked cyber activity and detection/enrichment coverage. Microsoft’s March 2026 Patch Tuesday (77 vulnerabilities) was summarized, highlighting CVE-2026-21262 (SQL Server elevation-of-priv/8
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- ce87f68ee57076c648e69d174cbab55245811a80aff66b59e9b268e72e1ed360
- Enrichment time
- 2026-03-15T07:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.