Metasploit Framework Updates with 16 New Modules, Targeting KEV Vulnerabilities
Metasploit has released sixteen new modules, including ten exploits, with five targeting vulnerabilities listed on the CISA Known Exploited Vulnerabilities (KEV) catalog.

The Metasploit Framework has seen a significant update with the addition of sixteen new modules, enhancing its capabilities for penetration testers and security researchers. This latest release includes ten new exploit modules, five of which specifically target vulnerabilities that have been added to the CISA Known Exploited Vulnerabilities (KEV) list, indicating active exploitation in the wild.
Among the newly added exploits are modules for critical vulnerabilities affecting Cisco Secure Firewall Management Center (CVE-2026-20079), SonicWall SMA1000 (CVE-2026-83549), and JetBrains TeamCity (CVE-2026-63077). These additions provide security professionals with updated tools to test defenses against some of the most pressing threats currently being leveraged by malicious actors.
The update also introduces modules for a range of other software, including Elasticsearch, SPIP, and a module for exploiting a Kerberos relay attack. The Elasticsearch module, for instance, addresses an XXE vulnerability in Apache Tika's XFA parser within the attachment ingest processor (CVE-2025-66516). Meanwhile, a SPIP module targets an unauthenticated blind SQL injection vulnerability.
Further expanding its utility, Metasploit now includes a module for detecting Metasploit payload handlers across TCP, UDP, HTTP, and HTTPS protocols, aiding in the identification of active listener sessions. Additionally, a Linux x64 sandbox evasion module has been integrated, designed to perform runtime environment checks and abort execution if a sandbox or virtual machine is detected, assisting in stealthier operations.
The SonicWall SMA1000 exploit module is particularly noteworthy, addressing a chain of vulnerabilities including SSRF and RCE. This chain was recently disclosed as being exploited in the wild, with the Metasploit module targeting CVE-2026-83549, a command injection flaw that allows for root-level remote code execution. The patched version 12.5.0-02952 is noted as the remediation.
For JetBrains TeamCity, the new module targets CVE-2026-63077, an unauthenticated RCE vulnerability stemming from an unsafe XStream deserialization flaw in the agent polling protocol. The module supports both Windows and Linux targets and includes cleanup logic to remove the fake build agent created during exploitation.
Other notable additions include exploits for Langflow AI (CVE-2026-19295), MCPJam Inspector (CVE-2026-23744), and PaperCut NG/MF (CVE-2026-82078). The PaperCut exploit module targets a chain that was recently reported as a zero-day being actively exploited, enabling RCE and domain admin access.
This comprehensive update underscores the ongoing efforts by the Metasploit development community to keep pace with emerging threats and provide essential tools for cybersecurity professionals to assess and improve their security postures against actively exploited vulnerabilities.