{"slug": "metasploit-wrap-up-a-collection-of-what-can-only-be-called-eclectic-modules", "title": "Metasploit Wrap Up: A Collection of What Can Only Be Called Eclectic Modules", "summary": "Metasploit's latest release adds 12 new modules, including four targeting LLMs and AI infrastructure: a scanner for CVE-2026-22778 in vLLM's multimodal endpoint, an unauthenticated RCE in Langflow versions 1.7.3 and below (CVE-2026-0770), a command-injection exploit in BerriAI LiteLLM proxy's MCP test REST endpoints (CVE-2026-42271), and a path-traversal persistence exploit in Ollama's Windows auto-update. The release also ships two Linux local privilege-escalation exploits, 12 Windows AARCH64 fetch payloads, a dizqueTV streaming RCE, and a scanner for CVE-2000-0979, a 26-year-old SMB share password flaw. The vLLM flaw leaks a heap address when an invalid image is sent to the multimodal endpoint, which can be chained with a heap overflow to achieve remote code execution.", "body_md": "\n\n```\nI’m not sure how else to describe this release’s module content. Four modules targeting LLMs, two Linux LPE’s, 12 Windows AARCH64 fetch payloads, a TV streaming RCE, and a scanner targeting a CVE from 26 years ago? It is a privilege to work with committers and contributors with such varied passions, and who knows, next release we might have a Novell Netware module and then we really will party like it’s 1999!\nNew module content (12)\nvLLM Multimodal Heap-Address Information Leak Scanner\nAuthor: Kenneth LaCroix\nType: Auxiliary\nPull request: #21592 contributed by kenlacroix\nPath: scanner/http/vllm_multimodal_info_leak\nCVE reference: CVE-2026-22778\nDescription: This adds an auxiliary scanner module vllm_multimodal_info_leak that detects vLLM OpenAI-compatible servers affected by CVE-2026-22778. The aforementioned CVE tracks a vulnerability that when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error which contains a heap address that can be chained with a heap overflow to achieve RCE on the target system.\nCVE-2000-0979 SMB Share Password Enumerator\nAuthors: Azbil SecurityFriday Co Ltd and Zoltan Balazs <zoltan1.balazs <Zoltan Balazs [email protected] @zh4ck>\nType: Auxiliary\nPull request: #0\nPath: scanner/smb/cve_2000_0979\nCVE reference: CVE-2000-0979\nDescription: Unable to find PR information, please complete manually\nN-able N-central Struts BeanUtils Unauthenticated RCE\nAuthor: sfewer-r7\nType: Exploit\nPull request: #21896 contributed by sfewer-r7\nPath: linux/http/nable_ncentral_unauth_rce_cve_2026_86218\nCVE reference: CVE-2026-86218\nDescription: This adds an exploit module for CVE-2026-86218, unauthenticated RCE against N-able N-central versions 2026.3.1.13 and below.\nLocal Privilege Escalation in snapd\nAuthors: Qualys Security Advisory Team and msutovsky-r7\nType: Exploit\nPull request: #21532 contributed by msutovsky-r7\nPath: linux/local/cve_2026_3888\nCVE reference: CVE-2026-3888\nDescription: Adds a module targeting CVE-2026-3888, a TOCTOU race condition in snap-confine, the\nSUID binary used by the snapd package manager to enforce snap sandbox boundaries.\nDirtyClone LPE\nAuthors: Eddy Tsalolikhin, Or Peles, and msutovsky-r7\nType: Exploit\nPull request: #21613 contributed by eipoverflow\nPath: linux/local/dirtyclone_cve_2026_43503\nCVE reference: CVE-2026-43503\nDescription: This adds a local exploit module for DirtyClone.\ndizqueTV Unauthenticated Remote Code Execution\nAuthors: Ahmed Said Saud Al-Busaidi and Muhammad Sulthon Nurbahari\nType: Exploit\nPull request: #21787 contributed by 0x5chltz\nPath: multi/http/dizquetv_rce\nCVE reference: CVE-2024-58286\nDescription: Adds an exploit module for EDB-52079, an unauthenticated remote code execution targeting dizqueTV, a Node.js-based IPTV streaming server.\nLangflow Unauthenticated RCE (validate endpoint)\nAuthors: Diamorphine and bhaskarbhar\nType: Exploit\nPull request: #21750 contributed by bhaskarbhar\nPath: multi/http/langflow_rce_cve_2026_0770\nCVE reference: CVE-2026-0770\nDescription: Adds a module targeting CVE-2026-0770, an unauthenticated remote code execution in Langflow versions <= 1.7.3.\nBerriAI LiteLLM Proxy MCP Test Endpoint Command Execution\nAuthor: Kenneth LaCroix\nType: Exploit\nPull request: #21585 contributed by kenlacroix\nPath: multi/http/litellm_mcp_test_cmd_injection\nCVE reference: CVE-2026-42271\nDescription: Adds an exploit module for CVE-2026-42271, a command execution flaw in the\nBerriAI LiteLLM proxy's MCP \"test\" REST endpoints.\nOpenCTI JSON Mapper safeEjs Sandbox Escape RCE\nAuthor: Ege Balci\nType: Exploit\nPull request: #21884 contributed by EgeBalci\nPath: multi/http/opencti_jsonmapper_safeejs_rce\nDescription: This adds a sandbox escape exploit for OpenCTI's SafeJS to achieve RCE as root inside the platform's API container in versions >= 6.8.16.\nOllama Windows Auto-Update Path Traversal Persistence\nAuthors: Bartłomiej Dmitruk and h00die\nType: Exploit\nPull request: #21423 contributed by h00die\nPath: windows/persistence/ollama_auto_update\nCVE reference: CVE-2026-42249\nDescription: This adds a persistence module for ollama auto update.\nFTP, HTTP, HTTPS and TFTP Fetch, Windows AArch64 Command Execution\nAuthors: Alexander \"xaitax\" Hagenah, Brendan Watters, and alanfoster\nType: Payload (Adapter)\nPull request: #21890 contributed by vinicius-batistella\nDescription: Adds Windows AArch64 fetch adapters.\nThis adapter adds the following payloads:\n\ncmd/windows/ftp/aarch64/exec\ncmd/windows/ftp/aarch64/shell/reverse_tcp\ncmd/windows/ftp/aarch64/shell_reverse_tcp\ncmd/windows/http/aarch64/exec\ncmd/windows/http/aarch64/shell/reverse_tcp\ncmd/windows/http/aarch64/shell_reverse_tcp\ncmd/windows/https/aarch64/exec\ncmd/windows/https/aarch64/shell/reverse_tcp\ncmd/windows/https/aarch64/shell_reverse_tcp\ncmd/windows/tftp/aarch64/exec\ncmd/windows/tftp/aarch64/shell/reverse_tcp\ncmd/windows/tftp/aarch64/shell_reverse_tcp\n\nLinux PAM Backdoor\nAuthor: h00die\nType: Post\nPull request: #21516 contributed by h00die\nPath: linux/manage/pam_backdoor\nDescription: Adds a module allowing a user to upload a pam so file (or compile on system if not x64) into the auth chain.\nEnhancements and features (4)\n\n#21680 from messede-degod - This updates the post/linux/gather/enum_protections module to detect AV/EDR inside the target system.\n#21887 from dwelch-r7 - Adds a Rake-based module generator (rake msf:generate[TYPE,PATH,PLATFORM,ARCH]) that scaffolds new modules skeletons for all available module types, together with a matching documentation skeleton under documentation/modules/.\n#21935 from jheysel-r7 - Adds additional fingerprint support for Gitlab 19.0.0-19.4.0.\n#21936 from satanonsteroids2024-zzz - Improves msfvenom option handling error message.\n\nBugs fixed (8)\n\n#21548 from msutovsky-r7 - Adds documentation and Improves reliability for fileless fetch payloads using the shell-search option on systems where anonymous file handles either don't exist or existing user does not have permission to write the payload into them.\n#21878 from Benziza - Fixes search type:-aux so the aux shorthand correctly excludes auxiliary modules, matching the behavior of search  type:-auxiliary.\n#21882 from revanth3205 - Fixes some exists? checks to now more accurately check for .directory? in several modules.\n#21906 from Pushpenderrathore - Fixes a bug in the Web Enrollment library where a dropped connection or timeout between the request to create the certificate and the request to download the certificate. Previously the timeout was unhandled which caused the module to stop without downloading the certificate that had been created. This change handles the exception and prints out the warning.\n#21923 from kx7m2qd - Fixes some exists? checks to now more accurately check for .directory? and writable? in several modules.\n#21959 from revanth3205 - Fixes missing ip:port prefixes for the console output in the MSSQL and SSH login scanners.\n#21969 from pauljccode - Freeze time in the rate limiter concurrency spec.\n#21982 from kx7m2qd - Fixes duplicate ip:port prefixes in the output of the PostgreSQL login scanner.\n\nDocumentation\nYou can find the latest Metasploit documentation on our docsite at docs.metasploit.com.\nErrors (1)\nPLEASE IDENTIFY THE ERRORS BELOW AND FIX MANUALLY AS PART OF YOUR WRITE UP\n\n#-1 from unknown-value-for-login - Error - could not find pull request 'Merge pull request #21072 from Z6543/add-cve-2000-0979-module Add module for CVE-2000-0979 Windows 9x/Me SMB share password enumeration' for commit '06d58967fc049479241903e8ab95c003f27c9c42' - verify the pull request message is valid\n\nGet it\nAs always, you can update to the latest Metasploit Framework with msfupdate\nand you can get more details on the changes since the last blog post from\nGitHub:\n\nPull Requests 6.5.5...6.5.6\nFull diff 6.5.5...6.5.6\n\nIf you are a git user, you can clone the Metasploit Framework repo (master branch) for the latest.\nTo install fresh without using git, you can use the open-source-only Nightly Installers or the\ncommercial edition Metasploit Pro\n```\n\n## Explore more from Rapid7\n\n### Vulnerability & Exploit Database\n\nRapid7s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.\n\nSearch the database\n\n### Rapid7 Labs\n\nThe threat research behind the alerts: adversary tracking, curated intelligence, and flagship threat reports.\n\nExplore the research\n\n### Rapid7 MDR\n\nGain 24x7 XDR monitoring, remediation, and DFIR from experts that extend your team to help secure your extended ecosystem.\n\nExplore MDR\n\n### Exposure management\n\nGet continuous assessment of your attack surface with the critical context to validate and extinguish vulnerabilities and policy gaps.\n\nSee how it works", "url": "https://wpnews.pro/news/metasploit-wrap-up-a-collection-of-what-can-only-be-called-eclectic-modules", "canonical_source": "https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-a-collection-of-what-can-only-be-called-eclectic-modules", "published_at": "2026-10-09 11:00:52+00:00", "updated_at": "2026-10-09 11:25:06.538449+00:00", "lang": "en", "topics": ["ai-safety", "ai-infrastructure", "large-language-models", "ai-tools", "mlops"], "entities": ["Metasploit", "vLLM", "Langflow", "BerriAI LiteLLM", "Ollama", "OpenCTI", "dizqueTV", "N-able N-central"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/metasploit-wrap-up-a-collection-of-what-can-only-be-called-eclectic-modules", "markdown": "https://wpnews.pro/news/metasploit-wrap-up-a-collection-of-what-can-only-be-called-eclectic-modules.md", "text": "https://wpnews.pro/news/metasploit-wrap-up-a-collection-of-what-can-only-be-called-eclectic-modules.txt", "jsonld": "https://wpnews.pro/news/metasploit-wrap-up-a-collection-of-what-can-only-be-called-eclectic-modules.jsonld"}}