threat_intelligence1028 wordsRead on Huntaegis

Metasploit Wrap Up: A Collection of What Can Only Be Called Eclectic Modules

I’m not sure how else to describe this release’s module content. Four modules targeting LLMs, two Linux LPE’s, 12 Windows AARCH64 fetch payloads, a TV streaming RCE, and a scanner targeting a CVE from 26 years ago? It is a privilege to work with committers and contributors with such varied passions, and who knows, next release we might have a Novell Netware module and then we really will party like it’s 1999! New module content (12) vLLM Multimodal Heap-Address Information Leak Scanner Author: Kenneth LaCroix Type: Auxiliary Pull request: #21592 contributed by kenlacroix Path: scanner/http/vllm_multimodal_info_leak CVE reference: CVE-2026-22778 Description: This adds an auxiliary scanner module vllm_multimodal_info_leak that detects vLLM OpenAI-compatible servers affected by CVE-2026-22778. The aforementioned CVE tracks a vulnerability that when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error which contains a heap address that can be chained with a heap overflow to achieve RCE on the target system. CVE-2000-0979 SMB Share Password Enumerator Authors: Azbil SecurityFriday Co Ltd and Zoltan Balazs Type: Auxiliary Pull request: #0 Path: scanner/smb/cve_2000_0979 CVE reference: CVE-2000-0979 Description: Unable to find PR information, please complete manually N-able N-central Struts BeanUtils Unauthenticated RCE Author: sfewer-r7 Type: Exploit Pull request: #21896 contributed by sfewer-r7 Path: linux/http/nable_ncentral_unauth_rce_cve_2026_86218 CVE reference: CVE-2026-86218 Description: This adds an exploit module for CVE-2026-86218, unauthenticated RCE against N-able N-central versions 2026.3.1.13 and below. Local Privilege Escalation in snapd Authors: Qualys Security Advisory Team and msutovsky-r7 Type: Exploit Pull request: #21532 contributed by msutovsky-r7 Path: linux/local/cve_2026_3888 CVE reference: CVE-2026-3888 Description: Adds a module targeting CVE-2026-3888, a TOCTOU race condition in snap-confine, the SUID binary used by the snapd package manager to enforce snap sandbox boundaries. DirtyClone LPE Authors: Eddy Tsalolikhin, Or Peles, and msutovsky-r7 Type: Exploit Pull request: #21613 contributed by eipoverflow Path: linux/local/dirtyclone_cve_2026_43503 CVE reference: CVE-2026-43503 Description: This adds a local exploit module for DirtyClone. dizqueTV Unauthenticated Remote Code Execution Authors: Ahmed Said Saud Al-Busaidi and Muhammad Sulthon Nurbahari Type: Exploit Pull request: #21787 contributed by 0x5chltz Path: multi/http/dizquetv_rce CVE reference: CVE-2024-58286 Description: Adds an exploit module for EDB-52079, an unauthenticated remote code execution targeting dizqueTV, a Node.js-based IPTV streaming server. Langflow Unauthenticated RCE (validate endpoint) Authors: Diamorphine and bhaskarbhar Type: Exploit Pull request: #21750 contributed by bhaskarbhar Path: multi/http/langflow_rce_cve_2026_0770 CVE reference: CVE-2026-0770 Description: Adds a module targeting CVE-2026-0770, an unauthenticated remote code execution in Langflow versions <= 1.7.3. BerriAI LiteLLM Proxy MCP Test Endpoint Command Execution Author: Kenneth LaCroix Type: Exploit Pull request: #21585 contributed by kenlacroix Path: multi/http/litellm_mcp_test_cmd_injection CVE reference: CVE-2026-42271 Description: Adds an exploit module for CVE-2026-42271, a command execution flaw in the BerriAI LiteLLM proxy's MCP "test" REST endpoints. OpenCTI JSON Mapper safeEjs Sandbox Escape RCE Author: Ege Balci Type: Exploit Pull request: #21884 contributed by EgeBalci Path: multi/http/opencti_jsonmapper_safeejs_rce Description: This adds a sandbox escape exploit for OpenCTI's SafeJS to achieve RCE as root inside the platform's API container in versions >= 6.8.16. Ollama Windows Auto-Update Path Traversal Persistence Authors: Bartłomiej Dmitruk and h00die Type: Exploit Pull request: #21423 contributed by h00die Path: windows/persistence/ollama_auto_update CVE reference: CVE-2026-42249 Description: This adds a persistence module for ollama auto update. FTP, HTTP, HTTPS and TFTP Fetch, Windows AArch64 Command Execution Authors: Alexander "xaitax" Hagenah, Brendan Watters, and alanfoster Type: Payload (Adapter) Pull request: #21890 contributed by vinicius-batistella Description: Adds Windows AArch64 fetch adapters. This adapter adds the following payloads: cmd/windows/ftp/aarch64/exec cmd/windows/ftp/aarch64/shell/reverse_tcp cmd/windows/ftp/aarch64/shell_reverse_tcp cmd/windows/http/aarch64/exec cmd/windows/http/aarch64/shell/reverse_tcp cmd/windows/http/aarch64/shell_reverse_tcp cmd/windows/https/aarch64/exec cmd/windows/https/aarch64/shell/reverse_tcp cmd/windows/https/aarch64/shell_reverse_tcp cmd/windows/tftp/aarch64/exec cmd/windows/tftp/aarch64/shell/reverse_tcp cmd/windows/tftp/aarch64/shell_reverse_tcp Linux PAM Backdoor Author: h00die Type: Post Pull request: #21516 contributed by h00die Path: linux/manage/pam_backdoor Description: Adds a module allowing a user to upload a pam so file (or compile on system if not x64) into the auth chain. Enhancements and features (4) - #21680 from messede-degod - This updates the post/linux/gather/enum_protections module to detect AV/EDR inside the target system. - #21887 from dwelch-r7 - Adds a Rake-based module generator ( rake msf:generate[TYPE,PATH,PLATFORM,ARCH] ) that scaffolds new modules skeletons for all available module types, together with a matching documentation skeleton underdocumentation/modules/ . - #21935 from jheysel-r7 - Adds additional fingerprint support for Gitlab 19.0.0-19.4.0. - #21936 from satanonsteroids2024-zzz - Improves msfvenom option handling error message. Bugs fixed (8) - #21548 from msutovsky-r7 - Adds documentation and Improves reliability for fileless fetch payloads using the shell-search option on systems where anonymous file handles either don't exist or existing user does not have permission to write the payload into them. - #21878 from Benziza - Fixes search type:-aux so the aux shorthand correctly excludes auxiliary modules, matching the behavior ofsearch type:-auxiliary . - #21882 from revanth3205 - Fixes some exists? checks to now more accurately check for.directory? in several modules. - #21906 from Pushpenderrathore - Fixes a bug in the Web Enrollment library where a dropped connection or timeout between the request to create the certificate and the request to download the certificate. Previously the timeout was unhandled which caused the module to stop without downloading the certificate that had been created. This change handles the exception and prints out the warning. - #21923 from kx7m2qd - Fixes some exists? checks to now more accurately check for.directory? andwritable? in several modules. - #21959 from revanth3205 - Fixes missing ip:port prefixes for the console output in the MSSQL and SSH login scanners. - #21969 from pauljccode - Freeze time in the rate limiter concurrency spec. - #21982 from kx7m2qd - Fixes duplicate ip:port prefixes in the output of the PostgreSQL login scanner. Documentation You can find the latest Metasploit documentation on our docsite at docs.metasploit.com. Errors (1) PLEASE IDENTIFY THE ERRORS BELOW AND FIX MANUALLY AS PART OF YOUR WRITE UP - #-1 from unknown-value-for-login - Error - could not find pull request 'Merge pull request #21072 from Z6543/add-cve-2000-0979-module Add module for CVE-2000-0979 Windows 9x/Me SMB share password enumeration' for commit '06d58967fc049479241903e8ab95c003f27c9c42' - verify the pull request message is valid Get it As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub: If you are a git user, you can clone the Metasploit Framework repo (master branch) for the latest. To install fresh without using git, you can use the open-source-only Nightly Installers or the commercial edition Metasploit Pro

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.