This release has something for everyone: scanner modules, payloads, and exploits. This release’s scanners cover Drupal, PanOS, WordPress, and SCADA; this release’s exploits cover Tenable, Flowise, CheckPoint, Langflow, Ruby, and SPIP.
New module content (16)
Forgejo Arbitrary File Read via Org-mode Include
Authors: NightRang3r and xbow-security
Type: Auxiliary
Pull request: #21778 contributed by jvoisin
Path: gather/forgejo_orgmode_fileread_cve_2026_59774
Description: Adds module targeting CVE-2026-59774, an arbitrary file read in Forgejo 7.0 through 15.0.5 and 16.0.0–16.0.1.
Wordpress Planyo Online Reservation System Arbitrary File Read (CVE-2026-3576)
Authors: Balachandar Gowrisankar and sinn3r [email protected]
Type: Auxiliary
Pull request: #21769 contributed by anirbala98
Path: gather/wp_planyo_lfi_cve_2026_3576
Description: This adds a module for, CVE-2026-3576, a local file inclusion vulnerability via server side request forgery in WordPress's Planyo Online Reservation System plugin (versions < 3.1). The plugin's AJAX proxy ulap.php does not validate the scheme of URLs supplied to it. This allows unauthenticated attackers to supply file:// URLs to ulap.php and retrieve any arbitrary local file contents from the target.
Concrete CMS Unauthenticated File Usage Disclosure
Author: dividesbyzer0
Type: Auxiliary
Pull request: #21695 contributed by zoomdbz
Path: scanner/http/concrete_cms_file_usage_disclosure
Description: Adds an auxiliary scanner module for CVE-2026-6826: Concrete CMS 9.x before 9.5.1 exposes the file usage dialog controller at /ccm/system/dialogs/file/usage/<fID> without a view permission check.
Drupal Core PostgreSQL EntityQuery SQL Injection
Author: Lukas Johannes Moeller
Type: Auxiliary
Pull request: #21765 contributed by JohannesLks
Path: scanner/http/drupal_pgsql_entityquery_sqli
Description: This adds a new module: drupal_pgsql_entityquery_sqli for CVE-2026-9082, an unauthenticated SQL injection in Drupal core's PostgreSQL EntityQuery condition handler. The module confirms the injection using the framework's PostgreSQL time-based blind SQLi implementation.
PAN-OS GlobalProtect CAS CVE-2026-0265 Vulnerability Checker
Authors: Bishop Fox Team X and Rapid7 Research / Deral Heiland adaptation
Type: Auxiliary
Pull request: #21610 contributed by percx
Path: scanner/http/panos_cve_2026_0265
Description: Adds a new Metasploit auxiliary scanner module for safely detecting CVE-2026-0265 affecting PAN-OS GlobalProtect portals when Clientless Application Services (CAS) authentication is enabled.
WordPress Core wp2shell Unauthenticated SQL Injection via REST Batch Route Confusion
Authors: Searchlight Cyber and dividesbyzer0
Type: Auxiliary
Pull request: #21694 contributed by zoomdbz
Path: scanner/http/wordpress_wp2shell_sqli
Description: Adds an auxiliary scanner module for the "wp2shell" WordPress core unauthenticated SQL injection: REST batch route confusion (CVE-2026-63030) chained with the WP_Query author__not_in string interpolation (CVE-2026-60137). Affects WordPress core 6.9.0-6.9.4 and 7.0.0-7.0.1 (fixed in 6.9.5 / 7.0.2, 2026-07-17).
Inductive Automation Ignition Gateway Fingerprint
Author: Ethan Thomason [email protected]
Type: Auxiliary
Pull request: #21603 contributed by ethan-thomason
Path: scanner/scada/ignition_statusping
Description: Adds an auxiliary scanner module that fingerprints Inductive Automation Ignition gateways across all major version families by probing unauthenticated info endpoints.
OPC-UA Server Detection
Author: Ethan Thomason [email protected]
Type: Auxiliary
Pull request: #21612 contributed by ethan-thomason
Path: scanner/scada/opcua_enum
Description: Adds auxiliary/scanner/scada/opcua_enum, a scanner module that detects OPC-UA servers speaking the OPC-UA TCP binary transport (opc.tcp://).
Tenable Security Center SCAP Audit File Command Injection
Author: h00die
Type: Exploit
Pull request: #21802 contributed by h00die
Path: linux/http/tenable_sc_auditfile_cmdinject_cve_2026_19681
Description: Adds a module for CVE-2026-19681, an authenticated remote code execution vulnerability against Tenable Security Center.
Tenable Security Center Report Charting RCE
Author: h00die
Type: Exploit
Pull request: #21820 contributed by h00die
Path: linux/http/tenable_sc_report_charting_rce_cve_2026_19626
Description: Adds a module for CVE-2026-21820, an authenticated remote code execution vulnerability in Tenable Security Center.
Check Point SmartConsole Authentication Bypass Run Script RCE
Author: sfewer-r7
Type: Exploit
Pull request: #21731 contributed by sfewer-r7
Path: linux/misc/checkpoint_smartconsole_cve_2026_16232_rce
Description: Not written - add release notes directly to the pull request, then regenerate. Do not edit manually without ensuring the pull request has the release note present.
Flowise MCP Server Remote Code Execution
Authors: ABDUL JAFAROV https://github.com/jafarov007 and cn-panda
Type: Exploit
Pull request: #21616 contributed by jafarov007
Path: multi/http/flowise_mcp_rce
Description: Adds a new exploit module for CVE-2026-56274, a remote code execution vulnerability in Flowise versions prior to 3.1.2.
Langflow AI auto_login RCE
Author: Richard Howe <rhowe425>
Type: Exploit
Pull request: #21753 contributed by rmhowe425
Path: multi/http/langflow_unauth_rce_cve_2026_9198
Description: Adds an exploit module for CVE-2026-9198, an unauthorized RCE vulnerability in Langflow versions 1.10.0 and below.
Ruby on Rails Active Storage Vips Arbitrary File Read and Remote Code Execution
Authors: 0xacb, Crypto-Cat, RyotaK, castilho, and s3np41k1r1t0
Type: Exploit
Pull request: #21733 contributed by jburgess-r7
Path: multi/http/rails_activestorage_vips_rce
Description: This adds an exploit module for CVE-2026-66066, a remote code execution vulnerability in Ruby on Rails Active Storage. The module chains a libvips arbitrary file read (via crafted HDF5/MATLAB images) with secret_key_base recovery to achieve RCE through the ImageProcessing gem, supporting Unix command, Linux fetch, and native Ruby payload targets.
SPIP X-Spip-Filtre Unauthenticated RCE
Author: Julien Voisin
Type: Exploit
Pull request: #21790 contributed by jvoisin
Path: multi/http/spip_x_spip_filtre_rce
Description: This module exploits a PHP function-call injection in SPIP's template engine before versions 4.4.21 to achieve unauthenticated RCE. The analyse_resultat_skel() function extracts <?php header("X-Spip-Filtre: ..."); ?> patterns from the rendered page body and calls the listed functions as template filters.
Linux Execute Command exec() payload
Author: Diego Ledda
Type: Payload (Single)
Pull request: #21445 contributed by dledda-r7
Path: linux/mips64/exec
Description: Adds MIPS64 exec payload, MIPSEL and MIPSBE exec payload update, and prepends for all three.
Enhanced Modules (1)
Modules which have either been enhanced, or renamed:
- #21795 from vognik - Updates the Ghost CMS authenticated RCE module to construct an Origin header that matches Ghost’s canonical site URL by omitting standard ports (80/443) while keeping non-standard ports, preventing Ghost’s strict RFC 6454 origin validation from rejecting requests.
Enhancements and features (8)
- #21378 from g0tmi1k - Cleans up the ftp_version module, offloading some methods to a mixin, increases comments, and removes unused options.
- #21402 from karanabe - Adds a SessionType option to
auxiliary/scanner/winrm/winrm_loginso successful WinRM logins can create either the existing cmd-backed shell, a PSRP-backed PowerShell session, or automatically fall back to PowerShell when cmd shell creation is denied. - #21496 from h00die - Not written - add release notes directly to the pull request, then regenerate. Do not edit manually without ensuring the pull request has the release note present.
- #21573 from jheysel-r7 - Adds support to the Post Mixin for Windows sessions to run the .writable? method.
- #21644 from dwelch-r7 - Improves start up performance of msfconsole.
- #21717 from eve0805 - Not written - add release notes directly to the pull request, then regenerate. Do not edit manually without ensuring the pull request has the release note present.
- #21779 from bwatters-r7 - This extends
windows/smb/psexecto work with aarch64 targets. - #21789 from h00die - Adds a new command line flag to print the count of modules.
Bugs fixed (11)
- #21184 from Hemang360 - Fix inconsistencies between report_service and create_credential.
- #21569 from dwelch-r7 - Not written - add release notes directly to the pull request, then regenerate. Do not edit manually without ensuring the pull request has the release note present.
- #21742 from dwelch-r7 - Replace
::Timeout.timeout+Queue#deq(false)withQueue#deq(timeout:)inTcpServerChannel#acceptto increase reliability in Ruby 3.x. - #21783 from eipoverflow - Bumps rex-bin_tools to bring in the changes from https://github.com/rapid7/rex-bin_tools/pull/16, which fixes a bug in the calculation of section sizes.
- #21784 from Pushpenderrathore - This pull request fixes two uncaught exceptions in the default DNS forward/cache path that would silently kill the listener thread when finalizing an empty response. The crashes were caused by incorrect method calls to the Dnsruby library, which have been updated to use the proper rcode= setter and #encode serializer. As a result, the DNS server now correctly handles and forwards out-of-scope queries without terminating.
- #21793 from h00die - fixes a bug in our rsync banner grab that was broken because rsync changed their banner in protocol 32.
- #21797 from d1mov - Corrects incorrect
checkmethod that failed to include Windows Server 2019, even though it is vulnerable. - #21799 from dledda-r7 - Adds automatic payload selection when changing targets.
- #21804 from dledda-r7 - Fixes a bug where shellcode prepends were added to the beginning of fetch command payloads rather than the beginning of the binary payloads delivered by fetch command payloads.
- #21816 from h00die - Fixes SSH Version scanner to work on ancient versions of SSH.
- #21832 from jheysel-r7 - This fixes an issue with the ldap_esc_vulnerable_cert_finder module where it wasn't properly rescuing an HTTPTimeout exception when the Domain Controller's WinRM service wouldn't respond to the module's version check. Now the module catches the exception and handles it properly allowing the module to continue preventing a crash.
Documentation added (1)
- #21809 from jamesgol - Updates the documentation on reporting vulns to match the changes R7 made to the pages for reporting vulns.
You can always find more documentation on our docsite at docs.metasploit.com.
Get it
As always, you can update to the latest Metasploit Framework with msfupdate
and you can get more details on the changes since the last blog post from
GitHub:
If you are a git user, you can clone the Metasploit Framework repo (master branch) for the latest.
To install fresh without using git, you can use the open-source-only Nightly Installers or the
commercial edition Metasploit Pro



