Metasploit Framework Bolsters Offensive Capabilities with Diverse New Modules
Rapid7's Metasploit Framework has been updated with a wide array of new modules, enhancing its utility for security professionals with exploits targeting LLMs, Linux, Windows, and legacy systems.

Rapid7 has released a significant update to its Metasploit Framework, introducing a diverse collection of new modules designed to expand the toolkit available to security researchers and penetration testers. This latest release features modules targeting a broad spectrum of vulnerabilities, from cutting-edge AI systems to long-standing software flaws, reflecting the ever-evolving threat landscape.
The update includes several modules focused on Large Language Models (LLMs), such as a scanner for the vLLM multimodal heap-address information leak (CVE-2026-22778). This vulnerability allows attackers to extract heap addresses that can be chained with other exploits to achieve remote code execution. Additionally, a module targets a command execution flaw in BerriAI LiteLLM proxy's MCP "test" REST endpoints (CVE-2026-42271).
For Linux environments, the framework now includes exploits for local privilege escalation vulnerabilities. One module targets a TOCTOU race condition in snapd (CVE-2026-3888), while another addresses the DirtyClone LPE vulnerability (CVE-2026-43503). The update also introduces a persistence module for Ollama on Windows, exploiting a path traversal flaw in its auto-update mechanism (CVE-2026-42249), alongside a suite of 12 new fetch payloads for Windows AArch64 systems.
Networked devices are not overlooked, with new exploits for a TV streaming RCE in dizqueTV (EDB-52079) and an unauthenticated RCE in Langflow (CVE-2026-0770). Furthermore, a sandbox escape exploit for OpenCTI's SafeJS aims to achieve RCE as root within the platform's API container.
In a nod to historical vulnerabilities, a new scanner module targets CVE-2000-0979, an SMB share password enumeration flaw dating back 26 years. This eclectic inclusion highlights the framework's commitment to providing comprehensive testing capabilities across different eras of software development.
Beyond new exploits, the update brings enhancements to existing modules, including improved detection of AV/EDR within target systems and expanded fingerprint support for GitLab. A new Rake-based module generator has also been introduced to streamline the creation of new module skeletons and associated documentation.
Several bugs have also been addressed, improving the reliability of fileless fetch payloads and enhancing error message handling in msfvenom. These fixes contribute to a more stable and efficient user experience for Metasploit users.
This broad range of new modules underscores Metasploit's continued relevance as a critical tool for security professionals, enabling them to test defenses against a wide array of current and legacy threats.