Metasploit Adds New Modules Targeting Linux RC4, BeyondTrust, and Registry Persistence
The latest Metasploit update, released on Fri, Feb 27, 2026, includes seven new modules, nine feature enhancements, and critical bug fixes. Key updates feature unauthenticated remote code execution (RCE) exploits for Ollama, BeyondTrust, and Grandstream…
The latest Metasploit update, released on Fri, Feb 27, 2026, includes seven new modules, nine feature enhancements, and critical bug fixes. Key updates feature unauthenticated remote code execution (RCE) exploits for Ollama, BeyondTrust, and Grandstream VoIP devices, as well as advanced evasion techniques for Linux environments.
Critical Remote Code Execution Exploits
The update introduces exploit chains targeting high-severity vulnerabilities across enterprise and artificial intelligence infrastructure.
Ollama Model Registry Path Traversal (CVE-2024-37032): This vulnerability, with a CVSS score of 8.8, allows exploitation of Ollama’s pull mechanism via path traversal, resulting in unauthenticated root RCE. BeyondTrust PRA and RS Command Injection (CVE-2026-1731): With a CVSS score of 9.9, this allows unauthenticated command injection in BeyondTrust Privileged Remote Access and Remote Support appliances. A new BeyondTrust helper library is included to streamline future module development. Grandstream GXP1600 Stack Overflow (CVE-2026-2329): This vulnerability, with a CVSS score of 9.3, targets VoIP devices to grant attackers a root session. The release includes one exploit module and two post-exploitation modules for credential theft and SIP traffic proxying.
Module Name CVE Target Module Type
Ollama Path Traversal RCE CVE-2024-37032 Linux / AI Exploit
The latest Metasploit update, released on Fri, Feb 27, 2026, includes seven new modules, nine feature enhancements, and critical bug fixes.
BeyondTrust PRA/RS RCE CVE-2026-1731 Appliances Exploit
Grandstream GXP1600 RCE CVE-2026-2329 VoIP Devices Exploit & Post
Linux RC4 Packer N/A ARM64 Linux Evasion
WSL Startup Persistence N/A Windows / WSL Exploit
Windows Active Setup N/A Windows Exploit
The update introduces the first Linux evasion module for ARM64 architectures, employing RC4 encryption and sleep evasion to bypass detection. New persistence modules for Windows and the Windows Subsystem for Linux (WSL) have been added, utilizing native OS features for payload execution.
Enhancements include improved check methods for Unreal IRCd and vsftpd backdoor modules, automated SRVHOST value selection for the SolarWinds exploit, and a new check method for the MS17-010 scanner. Bug fixes address issues in LDAP ESC and GraphQL Introspection scanners, eliminating crashes and false positives.
Based on reporting by Cyber Security News.
