Metasploit Wrap Up: A Collection of What Can Only Be Called Eclectic Modules

|Last updated on Oct 9, 2026|6 min read

I’m not sure how else to describe this release’s module content. Four modules targeting LLMs, two Linux LPE’s, 12 Windows AARCH64 fetch payloads, a TV streaming RCE, and a scanner targeting a CVE from 26 years ago? It is a privilege to work with committers and contributors with such varied passions, and who knows, next release we might have a Novell Netware module and then we really will party like it’s 1999!

New module content (12)

vLLM Multimodal Heap-Address Information Leak Scanner

Author: Kenneth LaCroix

Type: Auxiliary

Pull request: #21592 contributed by kenlacroix

Path: scanner/http/vllm_multimodal_info_leak

CVE reference: CVE-2026-22778

Description: This adds an auxiliary scanner module vllm_multimodal_info_leak that detects vLLM OpenAI-compatible servers affected by CVE-2026-22778. The aforementioned CVE tracks a vulnerability that when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error which contains a heap address that can be chained with a heap overflow to achieve RCE on the target system.

CVE-2000-0979 SMB Share Password Enumerator

Authors: Azbil SecurityFriday Co Ltd and Zoltan Balazs <zoltan1.balazs <Zoltan Balazs [email protected] @zh4ck>

Type: Auxiliary

Pull request: #0

Path: scanner/smb/cve_2000_0979

CVE reference: CVE-2000-0979

Description: Unable to find PR information, please complete manually

N-able N-central Struts BeanUtils Unauthenticated RCE

Author: sfewer-r7

Type: Exploit

Pull request: #21896 contributed by sfewer-r7

Path: linux/http/nable_ncentral_unauth_rce_cve_2026_86218

CVE reference: CVE-2026-86218

Description: This adds an exploit module for CVE-2026-86218, unauthenticated RCE against N-able N-central versions 2026.3.1.13 and below.

Local Privilege Escalation in snapd

Authors: Qualys Security Advisory Team and msutovsky-r7

Type: Exploit

Pull request: #21532 contributed by msutovsky-r7

Path: linux/local/cve_2026_3888

CVE reference: CVE-2026-3888

Description: Adds a module targeting CVE-2026-3888, a TOCTOU race condition in snap-confine, the SUID binary used by the snapd package manager to enforce snap sandbox boundaries.

DirtyClone LPE

Authors: Eddy Tsalolikhin, Or Peles, and msutovsky-r7

Type: Exploit

Pull request: #21613 contributed by eipoverflow

Path: linux/local/dirtyclone_cve_2026_43503

CVE reference: CVE-2026-43503

Description: This adds a local exploit module for DirtyClone.

dizqueTV Unauthenticated Remote Code Execution

Authors: Ahmed Said Saud Al-Busaidi and Muhammad Sulthon Nurbahari

Type: Exploit

Pull request: #21787 contributed by 0x5chltz

Path: multi/http/dizquetv_rce

CVE reference: CVE-2024-58286

Description: Adds an exploit module for EDB-52079, an unauthenticated remote code execution targeting dizqueTV, a Node.js-based IPTV streaming server.

Langflow Unauthenticated RCE (validate endpoint)

Authors: Diamorphine and bhaskarbhar

Type: Exploit

Pull request: #21750 contributed by bhaskarbhar

Path: multi/http/langflow_rce_cve_2026_0770

CVE reference: CVE-2026-0770

Description: Adds a module targeting CVE-2026-0770, an unauthenticated remote code execution in Langflow versions <= 1.7.3.

BerriAI LiteLLM Proxy MCP Test Endpoint Command Execution

Author: Kenneth LaCroix

Type: Exploit

Pull request: #21585 contributed by kenlacroix

Path: multi/http/litellm_mcp_test_cmd_injection

CVE reference: CVE-2026-42271

Description: Adds an exploit module for CVE-2026-42271, a command execution flaw in the BerriAI LiteLLM proxy's MCP "test" REST endpoints.

OpenCTI JSON Mapper safeEjs Sandbox Escape RCE

Author: Ege Balci

Type: Exploit

Pull request: #21884 contributed by EgeBalci

Path: multi/http/opencti_jsonmapper_safeejs_rce

Description: This adds a sandbox escape exploit for OpenCTI's SafeJS to achieve RCE as root inside the platform's API container in versions >= 6.8.16.

Ollama Windows Auto-Update Path Traversal Persistence

Authors: Bartłomiej Dmitruk and h00die

Type: Exploit

Pull request: #21423 contributed by h00die

Path: windows/persistence/ollama_auto_update

CVE reference: CVE-2026-42249

Description: This adds a persistence module for ollama auto update.

FTP, HTTP, HTTPS and TFTP Fetch, Windows AArch64 Command Execution

Authors: Alexander "xaitax" Hagenah, Brendan Watters, and alanfoster

Type: Payload (Adapter)

Pull request: #21890 contributed by vinicius-batistella

Description: Adds Windows AArch64 fetch adapters.

This adapter adds the following payloads:

  • cmd/windows/ftp/aarch64/exec
  • cmd/windows/ftp/aarch64/shell/reverse_tcp
  • cmd/windows/ftp/aarch64/shell_reverse_tcp
  • cmd/windows/http/aarch64/exec
  • cmd/windows/http/aarch64/shell/reverse_tcp
  • cmd/windows/http/aarch64/shell_reverse_tcp
  • cmd/windows/https/aarch64/exec
  • cmd/windows/https/aarch64/shell/reverse_tcp
  • cmd/windows/https/aarch64/shell_reverse_tcp
  • cmd/windows/tftp/aarch64/exec
  • cmd/windows/tftp/aarch64/shell/reverse_tcp
  • cmd/windows/tftp/aarch64/shell_reverse_tcp

Linux PAM Backdoor

Author: h00die

Type: Post

Pull request: #21516 contributed by h00die

Path: linux/manage/pam_backdoor

Description: Adds a module allowing a user to upload a pam so file (or compile on system if not x64) into the auth chain.

Enhancements and features (4)

  • #21680 from messede-degod - This updates the post/linux/gather/enum_protections module to detect AV/EDR inside the target system.
  • #21887 from dwelch-r7 - Adds a Rake-based module generator (rake msf:generate[TYPE,PATH,PLATFORM,ARCH]) that scaffolds new modules skeletons for all available module types, together with a matching documentation skeleton under documentation/modules/.
  • #21935 from jheysel-r7 - Adds additional fingerprint support for Gitlab 19.0.0-19.4.0.
  • #21936 from satanonsteroids2024-zzz - Improves msfvenom option handling error message.

Bugs fixed (8)

  • #21548 from msutovsky-r7 - Adds documentation and Improves reliability for fileless fetch payloads using the shell-search option on systems where anonymous file handles either don't exist or existing user does not have permission to write the payload into them.
  • #21878 from Benziza - Fixes search type:-aux so the aux shorthand correctly excludes auxiliary modules, matching the behavior of search type:-auxiliary.
  • #21882 from revanth3205 - Fixes some exists? checks to now more accurately check for .directory? in several modules.
  • #21906 from Pushpenderrathore - Fixes a bug in the Web Enrollment library where a dropped connection or timeout between the request to create the certificate and the request to download the certificate. Previously the timeout was unhandled which caused the module to stop without downloading the certificate that had been created. This change handles the exception and prints out the warning.
  • #21923 from kx7m2qd - Fixes some exists? checks to now more accurately check for .directory? and writable? in several modules.
  • #21959 from revanth3205 - Fixes missing ip:port prefixes for the console output in the MSSQL and SSH login scanners.
  • #21969 from pauljccode - Freeze time in the rate limiter concurrency spec.
  • #21982 from kx7m2qd - Fixes duplicate ip:port prefixes in the output of the PostgreSQL login scanner.

Documentation

You can find the latest Metasploit documentation on our docsite at docs.metasploit.com.

Errors (1)

PLEASE IDENTIFY THE ERRORS BELOW AND FIX MANUALLY AS PART OF YOUR WRITE UP

  • #-1 from unknown-value-for-login - Error - could not find pull request 'Merge pull request #21072 from Z6543/add-cve-2000-0979-module Add module for CVE-2000-0979 Windows 9x/Me SMB share password enumeration' for commit '06d58967fc049479241903e8ab95c003f27c9c42' - verify the pull request message is valid

Get it

As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:

If you are a git user, you can clone the Metasploit Framework repo (master branch) for the latest. To install fresh without using git, you can use the open-source-only Nightly Installers or the commercial edition Metasploit Pro

Article tags