Metasploit Wrap-Up 02/27/2026
2026-03-05T14:19:38Z•e65efbbcb43c32302c76cce853487df51782f24ae85f4f3a2a4c1d870df8453b
ARM64BeyondTrustCiscoGrandstreamOllamaRC4RCESIP-interceptionVoIPcommand-injectioncredential-harvestingevasionexploitin-the-wildmetasploitpath-traversalsecurity-advisorystack-overflowvulnerability
What happened
Rapid7 posts a Metasploit wrap-up and related advisories highlighting multiple new exploit modules, critical vulnerability support, and active exploitation. Key additions in Metasploit include an Ollama path traversal RCE (CVE-2024-37032) with chained unauthenticated root RCE, a Grandstream GXP1600 stack overflow (CVE-2026-2329) enabling credential harvesting and SIP interception, and updated BeyondTrust PRA/RS support for a command injection (CVE-2026-1731). The feed also calls out a critical Cisco Catalyst SD‑WAN authentication bypass exploited in the wild (CVE-2026-20127). Evasion and tool‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- e65efbbcb43c32302c76cce853487df51782f24ae85f4f3a2a4c1d870df8453b
- Enrichment time
- 2026-03-05T14:19:38Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.