Products and Tools

Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!

|Last updated on Aug 28, 2026|8 min read
Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!

This release has something for everyone: scanner modules, payloads, and exploits. This release’s scanners cover Drupal, PanOS, WordPress, and SCADA; this release’s exploits cover Tenable, Flowise, CheckPoint, Langflow, Ruby, and SPIP.

New module content (16)

Forgejo Arbitrary File Read via Org-mode Include

Authors: NightRang3r and xbow-security

Type: Auxiliary

Pull request: #21778 contributed by jvoisin

Path: gather/forgejo_orgmode_fileread_cve_2026_59774

Description: Adds module targeting CVE-2026-59774, an arbitrary file read in Forgejo 7.0 through 15.0.5 and 16.0.0–16.0.1.

Wordpress Planyo Online Reservation System Arbitrary File Read (CVE-2026-3576)

Authors: Balachandar Gowrisankar and sinn3r [email protected]

Type: Auxiliary

Pull request: #21769 contributed by anirbala98

Path: gather/wp_planyo_lfi_cve_2026_3576

Description: This adds a module for, CVE-2026-3576, a local file inclusion vulnerability via server side request forgery in WordPress's Planyo Online Reservation System plugin (versions < 3.1). The plugin's AJAX proxy ulap.php does not validate the scheme of URLs supplied to it. This allows unauthenticated attackers to supply file:// URLs to ulap.php and retrieve any arbitrary local file contents from the target.

Concrete CMS Unauthenticated File Usage Disclosure

Author: dividesbyzer0

Type: Auxiliary

Pull request: #21695 contributed by zoomdbz

Path: scanner/http/concrete_cms_file_usage_disclosure

Description: Adds an auxiliary scanner module for CVE-2026-6826: Concrete CMS 9.x before 9.5.1 exposes the file usage dialog controller at /ccm/system/dialogs/file/usage/<fID> without a view permission check.

Drupal Core PostgreSQL EntityQuery SQL Injection

Author: Lukas Johannes Moeller

Type: Auxiliary

Pull request: #21765 contributed by JohannesLks

Path: scanner/http/drupal_pgsql_entityquery_sqli

Description: This adds a new module: drupal_pgsql_entityquery_sqli for CVE-2026-9082, an unauthenticated SQL injection in Drupal core's PostgreSQL EntityQuery condition handler. The module confirms the injection using the framework's PostgreSQL time-based blind SQLi implementation.

PAN-OS GlobalProtect CAS CVE-2026-0265 Vulnerability Checker

Authors: Bishop Fox Team X and Rapid7 Research / Deral Heiland adaptation

Type: Auxiliary

Pull request: #21610 contributed by percx

Path: scanner/http/panos_cve_2026_0265

Description: Adds a new Metasploit auxiliary scanner module for safely detecting CVE-2026-0265 affecting PAN-OS GlobalProtect portals when Clientless Application Services (CAS) authentication is enabled.

WordPress Core wp2shell Unauthenticated SQL Injection via REST Batch Route Confusion

Authors: Searchlight Cyber and dividesbyzer0

Type: Auxiliary

Pull request: #21694 contributed by zoomdbz

Path: scanner/http/wordpress_wp2shell_sqli

Description: Adds an auxiliary scanner module for the "wp2shell" WordPress core unauthenticated SQL injection: REST batch route confusion (CVE-2026-63030) chained with the WP_Query author__not_in string interpolation (CVE-2026-60137). Affects WordPress core 6.9.0-6.9.4 and 7.0.0-7.0.1 (fixed in 6.9.5 / 7.0.2, 2026-07-17).

Inductive Automation Ignition Gateway Fingerprint

Author: Ethan Thomason [email protected]

Type: Auxiliary

Pull request: #21603 contributed by ethan-thomason

Path: scanner/scada/ignition_statusping

Description: Adds an auxiliary scanner module that fingerprints Inductive Automation Ignition gateways across all major version families by probing unauthenticated info endpoints.

OPC-UA Server Detection

Author: Ethan Thomason [email protected]

Type: Auxiliary

Pull request: #21612 contributed by ethan-thomason

Path: scanner/scada/opcua_enum

Description: Adds auxiliary/scanner/scada/opcua_enum, a scanner module that detects OPC-UA servers speaking the OPC-UA TCP binary transport (opc.tcp://).

Tenable Security Center SCAP Audit File Command Injection

Author: h00die

Type: Exploit

Pull request: #21802 contributed by h00die

Path: linux/http/tenable_sc_auditfile_cmdinject_cve_2026_19681

Description: Adds a module for CVE-2026-19681, an authenticated remote code execution vulnerability against Tenable Security Center.

Tenable Security Center Report Charting RCE

Author: h00die

Type: Exploit

Pull request: #21820 contributed by h00die

Path: linux/http/tenable_sc_report_charting_rce_cve_2026_19626

Description: Adds a module for CVE-2026-21820, an authenticated remote code execution vulnerability in Tenable Security Center.

Check Point SmartConsole Authentication Bypass Run Script RCE

Author: sfewer-r7

Type: Exploit

Pull request: #21731 contributed by sfewer-r7

Path: linux/misc/checkpoint_smartconsole_cve_2026_16232_rce

Description: Not written - add release notes directly to the pull request, then regenerate. Do not edit manually without ensuring the pull request has the release note present.

Flowise MCP Server Remote Code Execution

Authors: ABDUL JAFAROV https://github.com/jafarov007 and cn-panda

Type: Exploit

Pull request: #21616 contributed by jafarov007

Path: multi/http/flowise_mcp_rce

Description: Adds a new exploit module for CVE-2026-56274, a remote code execution vulnerability in Flowise versions prior to 3.1.2.

Langflow AI auto_login RCE

Author: Richard Howe <rhowe425>

Type: Exploit

Pull request: #21753 contributed by rmhowe425

Path: multi/http/langflow_unauth_rce_cve_2026_9198

Description: Adds an exploit module for CVE-2026-9198, an unauthorized RCE vulnerability in Langflow versions 1.10.0 and below.

Ruby on Rails Active Storage Vips Arbitrary File Read and Remote Code Execution

Authors: 0xacb, Crypto-Cat, RyotaK, castilho, and s3np41k1r1t0

Type: Exploit

Pull request: #21733 contributed by jburgess-r7

Path: multi/http/rails_activestorage_vips_rce

Description: This adds an exploit module for CVE-2026-66066, a remote code execution vulnerability in Ruby on Rails Active Storage. The module chains a libvips arbitrary file read (via crafted HDF5/MATLAB images) with secret_key_base recovery to achieve RCE through the ImageProcessing gem, supporting Unix command, Linux fetch, and native Ruby payload targets.

SPIP X-Spip-Filtre Unauthenticated RCE

Author: Julien Voisin

Type: Exploit

Pull request: #21790 contributed by jvoisin

Path: multi/http/spip_x_spip_filtre_rce

Description: This module exploits a PHP function-call injection in SPIP's template engine before versions 4.4.21 to achieve unauthenticated RCE. The analyse_resultat_skel() function extracts <?php header("X-Spip-Filtre: ..."); ?> patterns from the rendered page body and calls the listed functions as template filters.

Linux Execute Command exec() payload

Author: Diego Ledda

Type: Payload (Single)

Pull request: #21445 contributed by dledda-r7

Path: linux/mips64/exec

Description: Adds MIPS64 exec payload, MIPSEL and MIPSBE exec payload update, and prepends for all three.

Enhanced Modules (1)

Modules which have either been enhanced, or renamed:

  • #21795 from vognik - Updates the Ghost CMS authenticated RCE module to construct an Origin header that matches Ghost’s canonical site URL by omitting standard ports (80/443) while keeping non-standard ports, preventing Ghost’s strict RFC 6454 origin validation from rejecting requests.

Enhancements and features (8)

  • #21378 from g0tmi1k - Cleans up the ftp_version module, offloading some methods to a mixin, increases comments, and removes unused options.
  • #21402 from karanabe - Adds a SessionType option to auxiliary/scanner/winrm/winrm_login so successful WinRM logins can create either the existing cmd-backed shell, a PSRP-backed PowerShell session, or automatically fall back to PowerShell when cmd shell creation is denied.
  • #21496 from h00die - Not written - add release notes directly to the pull request, then regenerate. Do not edit manually without ensuring the pull request has the release note present.
  • #21573 from jheysel-r7 - Adds support to the Post Mixin for Windows sessions to run the .writable? method.
  • #21644 from dwelch-r7 - Improves start up performance of msfconsole.
  • #21717 from eve0805 - Not written - add release notes directly to the pull request, then regenerate. Do not edit manually without ensuring the pull request has the release note present.
  • #21779 from bwatters-r7 - This extends windows/smb/psexec to work with aarch64 targets.
  • #21789 from h00die - Adds a new command line flag to print the count of modules.

Bugs fixed (11)

  • #21184 from Hemang360 - Fix inconsistencies between report_service and create_credential.
  • #21569 from dwelch-r7 - Not written - add release notes directly to the pull request, then regenerate. Do not edit manually without ensuring the pull request has the release note present.
  • #21742 from dwelch-r7 - Replace ::Timeout.timeout + Queue#deq(false) with Queue#deq(timeout:) in TcpServerChannel#accept to increase reliability in Ruby 3.x.
  • #21783 from eipoverflow - Bumps rex-bin_tools to bring in the changes from https://github.com/rapid7/rex-bin_tools/pull/16, which fixes a bug in the calculation of section sizes.
  • #21784 from Pushpenderrathore - This pull request fixes two uncaught exceptions in the default DNS forward/cache path that would silently kill the listener thread when finalizing an empty response. The crashes were caused by incorrect method calls to the Dnsruby library, which have been updated to use the proper rcode= setter and #encode serializer. As a result, the DNS server now correctly handles and forwards out-of-scope queries without terminating.
  • #21793 from h00die - fixes a bug in our rsync banner grab that was broken because rsync changed their banner in protocol 32.
  • #21797 from d1mov - Corrects incorrect check method that failed to include Windows Server 2019, even though it is vulnerable.
  • #21799 from dledda-r7 - Adds automatic payload selection when changing targets.
  • #21804 from dledda-r7 - Fixes a bug where shellcode prepends were added to the beginning of fetch command payloads rather than the beginning of the binary payloads delivered by fetch command payloads.
  • #21816 from h00die - Fixes SSH Version scanner to work on ancient versions of SSH.
  • #21832 from jheysel-r7 - This fixes an issue with the ldap_esc_vulnerable_cert_finder module where it wasn't properly rescuing an HTTPTimeout exception when the Domain Controller's WinRM service wouldn't respond to the module's version check. Now the module catches the exception and handles it properly allowing the module to continue preventing a crash.

Documentation added (1)

  • #21809 from jamesgol - Updates the documentation on reporting vulns to match the changes R7 made to the pages for reporting vulns.

You can always find more documentation on our docsite at docs.metasploit.com.

Get it

As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:

If you are a git user, you can clone the Metasploit Framework repo (master branch) for the latest. To install fresh without using git, you can use the open-source-only Nightly Installers or the commercial edition Metasploit Pro

LinkedInFacebookXBluesky