Metasploit Wrap-Up 02/27/2026

2026-03-05T14:19:38Ze65efbbcb43c32302c76cce853487df51782f24ae85f4f3a2a4c1d870df8453b
ARM64BeyondTrustCiscoGrandstreamOllamaRC4RCESIP-interceptionVoIPcommand-injectioncredential-harvestingevasionexploitin-the-wildmetasploitpath-traversalsecurity-advisorystack-overflowvulnerability

What happened

Rapid7 posts a Metasploit wrap-up and related advisories highlighting multiple new exploit modules, critical vulnerability support, and active exploitation. Key additions in Metasploit include an Ollama path traversal RCE (CVE-2024-37032) with chained unauthenticated root RCE, a Grandstream GXP1600 stack overflow (CVE-2026-2329) enabling credential harvesting and SIP interception, and updated BeyondTrust PRA/RS support for a command injection (CVE-2026-1731). The feed also calls out a critical Cisco Catalyst SD‑WAN authentication bypass exploited in the wild (CVE-2026-20127). Evasion and tool‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
e65efbbcb43c32302c76cce853487df51782f24ae85f4f3a2a4c1d870df8453b
Enrichment time
2026-03-05T14:19:38Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Metasploit Wrap-Up 02/27/2026 · Baitaphish