Rapid7 has released a significant update to the Metasploit Framework, delivering powerful new exploit modules and critical vulnerability support.
The February 2026 release equips security teams with advanced tools to test unauthenticated remote code execution (RCE) flaws, sophisticated evasion methods, and new persistence techniques.
Critical Exploit Modules Added
Ollama Path Traversal RCE
The standout addition is a new exploit module for Ollama AI infrastructure, tracked as CVE-2024-37032.
The vulnerability exists in Ollama’s model pull mechanism, which improperly accepts arbitrary path traversal sequences.
Attackers can exploit this by loading a rogue OCI registry to write malicious shared object files directly to the host system.
This action forces the Ollama service to spawn a new process, ultimately resulting in an unauthenticated root RCE.
BeyondTrust Command Injection
The BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) exploit modules received major technical upgrades.
Security researchers can now actively test for a severe unauthenticated command injection vulnerability identified as CVE-2026-1731.
Alongside this specific exploit, the update introduces a unified library containing BeyondTrust helper functions, which significantly improves the reliability of legacy support for older vulnerabilities.
Grandstream VoIP Exploitation
The testing framework now aggressively targets Grandstream GXP1600 series voice-over-IP devices. By exploiting a known stack overflow vulnerability (CVE-2026-2329), penetration testers can successfully secure a privileged root session.
Furthermore, Rapid7 added two specialized post-exploitation modules for these hardware devices, enabling extensive credential harvesting and deep SIP traffic packet capture for further analysis.
To help red teams bypass modern endpoint security controls, Metasploit introduced its first dedicated Linux evasion module designed specifically for ARM64 architectures.
This advanced module utilizes an RC4 encrypted packer, executes ELF binaries directly within the system memory, and employs sleep-based evasion tactics to hide malicious activity from automated security scanners.
For maintaining persistent network access, new exploit modules target both Windows and Linux environments.
One specific module abuses the built-in Windows Active Setup registry feature to stealthily launch payloads immediately upon user login.
Another clever persistence module targets the Windows Subsystem for Linux (WSL), writing malicious payloads directly into the user’s startup folder to ensure the connection survives system reboots.
Exploit Module Summary
Beyond the introduction of entirely new exploits, classic vulnerability modules received very important quality-of-life updates.
The legacy vsftpd and Unreal IRCd backdoor modules now feature highly improved checking methods, increased verbosity for troubleshooting, and native Meterpreter session support.
Additionally, Rapid7 engineers fixed several critical backend bugs, including an operational crash in the LDAP ESC scanner and annoying false positives within the GraphQL introspection scanner.
Follow us on Google News, LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google