
Latest Metasploit update is out with unauthenticated RCE for Grandstream GXP1600 VoIP devices, enabling credential harvesting and SIP interception. Also included is critical support for BeyondTrust PRA/RS command injection (CVE-2026-1731), plus a serious Ollama RCE (CVE-2024-37032). Check out the wrap up at https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-02-27-2026/
Post summary
The post announces new Metasploit modules delivering unauthenticated RCE for Grandstream GXP1600, command‑injection for BeyondTrust PRA/RS, and an Ollama RCE, offering ready‑to‑use exploit code for these CVEs.



