Metasploit Wrap Up: A Collection of What Can Only Be Called Eclectic Modules Metasploit's latest release adds 12 new modules, including four targeting LLMs and AI infrastructure: a scanner for CVE-2026-22778 in vLLM's multimodal endpoint, an unauthenticated RCE in Langflow versions 1.7.3 and below (CVE-2026-0770), a command-injection exploit in BerriAI LiteLLM proxy's MCP test REST endpoints (CVE-2026-42271), and a path-traversal persistence exploit in Ollama's Windows auto-update. The release also ships two Linux local privilege-escalation exploits, 12 Windows AARCH64 fetch payloads, a dizqueTV streaming RCE, and a scanner for CVE-2000-0979, a 26-year-old SMB share password flaw. The vLLM flaw leaks a heap address when an invalid image is sent to the multimodal endpoint, which can be chained with a heap overflow to achieve remote code execution. I’m not sure how else to describe this release’s module content. Four modules targeting LLMs, two Linux LPE’s, 12 Windows AARCH64 fetch payloads, a TV streaming RCE, and a scanner targeting a CVE from 26 years ago? It is a privilege to work with committers and contributors with such varied passions, and who knows, next release we might have a Novell Netware module and then we really will party like it’s 1999 New module content 12 vLLM Multimodal Heap-Address Information Leak Scanner Author: Kenneth LaCroix Type: Auxiliary Pull request: 21592 contributed by kenlacroix Path: scanner/http/vllm multimodal info leak CVE reference: CVE-2026-22778 Description: This adds an auxiliary scanner module vllm multimodal info leak that detects vLLM OpenAI-compatible servers affected by CVE-2026-22778. The aforementioned CVE tracks a vulnerability that when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error which contains a heap address that can be chained with a heap overflow to achieve RCE on the target system. CVE-2000-0979 SMB Share Password Enumerator Authors: Azbil SecurityFriday Co Ltd and Zoltan Balazs