{"id":11017,"date":"2026-02-28T10:03:42","date_gmt":"2026-02-28T10:03:42","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/02\/28\/metasploit-adds-new-modules-targeting-linux-rc4-beyondtrust-and-registry-persistence\/"},"modified":"2026-02-28T10:03:42","modified_gmt":"2026-02-28T10:03:42","slug":"metasploit-adds-new-modules-targeting-linux-rc4-beyondtrust-and-registry-persistence","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/02\/28\/metasploit-adds-new-modules-targeting-linux-rc4-beyondtrust-and-registry-persistence\/","title":{"rendered":"Metasploit Adds New Modules Targeting Linux RC4, BeyondTrust, and Registry Persistence"},"content":{"rendered":"<p>    Metasploit Adds New Modules Targeting Linux RC4, BeyondTrust, and Registry Persistence<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The latest Metasploit update, released on February 27, 2026, brings significant firepower to security professionals and <a href=\"https:\/\/cybersecuritynews.com\/top-10-gpt-tools\/\" type=\"post\" id=\"109960\" target=\"_blank\" rel=\"noreferrer noopener\">penetration testers<\/a>. <\/p>\n<p>The release introduces seven new modules, nine feature enhancements, and critical bug fixes. <\/p>\n<p>Standout additions include unauthenticated remote code execution (RCE) exploits for Ollama, BeyondTrust, and Grandstream VoIP devices, alongside advanced evasion techniques for Linux environments.<\/p>\n<h2 class=\"wp-block-heading\" id=\"critical-remote-code-execution-exploits\"><strong>Critical Remote Code Execution Exploits<\/strong><\/h2>\n<p>This update delivers powerful exploit chains targeting<a href=\"https:\/\/cybersecuritynews.com\/google-chrome-security-patch-2\/\" type=\"post\" id=\"68155\" target=\"_blank\" rel=\"noreferrer noopener\"> high-severity vulnerabilities<\/a> across enterprise and artificial intelligence infrastructure.<\/p>\n<p><strong>Ollama Model Registry Path Traversal (CVE-2024-37032):<\/strong>\u00a0Carrying a CVSS score of 8.8, this flaw allows an attacker to exploit Ollama\u2019s pull mechanism using path traversal sequences. <\/p>\n<p>The module loads a rogue OCI registry to write malicious shared object files into the target. By forcing Ollama to spawn a new process, the malicious library is loaded, resulting in unauthenticated root RCE.<a href=\"https:\/\/strobes.co\/vi\/cve\/CVE-2024-37032\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a>\u200b<\/p>\n<p><strong>BeyondTrust PRA and RS Command Injection (CVE-2026-1731):<\/strong>\u00a0This critical vulnerability carries a CVSS score of 9.9 and allows unauthenticated command injection in <a href=\"https:\/\/cybersecuritynews.com\/beyondtrust-privileged-remote-access-vulnerability-actively-exploited-in-the-wild\/\" type=\"post\" id=\"88401\" target=\"_blank\" rel=\"noreferrer noopener\">BeyondTrust Privileged Remote Access <\/a>and Remote Support appliances. <\/p>\n<p>The update also introduces a new BeyondTrust helper library to streamline future module development.<a href=\"https:\/\/www.acaglobal.com\/industry-insights\/beyondtrust-patches-critical-rce-vulnerability-cve-2026-1731\/\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a>\u200b<\/p>\n<p><strong>Grandstream GXP1600 Stack Overflow (CVE-2026-2329):<\/strong>\u00a0Targeting VoIP devices, this critical flaw has a CVSS score of 9.3 and grants attackers a root session. <\/p>\n<p><a href=\"https:\/\/www.rapid7.com\/blog\/post\/pt-metasploit-wrap-up-02-27-2026\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Rapid7 release includes<\/a> one exploit module and two post-exploitation modules that leverage this access to steal credentials and proxy SIP traffic for packet capture.<a href=\"https:\/\/www.linkedin.com\/posts\/rajsamani_cve-2026-2329-critical-unauthenticated-stack-activity-7430245740708491264-BTIo\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a>\u200b<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">Module Name<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">CVE<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Target<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Module Type<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Ollama Path Traversal RCE<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">CVE-2024-37032<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Linux \/ AI<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Exploit<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">BeyondTrust PRA\/RS RCE<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">CVE-2026-1731<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Appliances<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Exploit<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Grandstream GXP1600 RCE<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">CVE-2026-2329<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">VoIP Devices<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Exploit &amp; Post<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Linux RC4 Packer<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">ARM64 Linux<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Evasion<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">WSL Startup Persistence<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Windows \/ WSL<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Exploit<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">Windows Active Setup<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Windows<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Exploit<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>A major highlight is the introduction of the first Linux evasion module for ARM64 architectures. <\/p>\n<p>The Linux RC4 Packer utilizes RC4 encryption, executes ELF binaries directly in memory, and employs sleep evasion to bypass detection mechanisms.<\/p>\n<p>Additionally, new persistence modules were added for Windows and the <a href=\"https:\/\/cybersecuritynews.com\/poc-exploit-released-for-actively-exploited\/\" type=\"post\" id=\"90491\" target=\"_blank\" rel=\"noreferrer noopener\">Windows Subsystem for Linux <\/a>(WSL). The WSL module writes payloads to the user\u2019s startup folder. <\/p>\n<p>Meanwhile, the Windows Registry Active Setup module launches payloads using native OS features. However, it downgrades permissions to user level and only executes once per user profile.<\/p>\n<h2 class=\"wp-block-heading\" id=\"key-enhancements-and-fixes\"><strong>Key Enhancements and Fixes<\/strong><\/h2>\n<p>Classic vulnerability modules received major quality-of-life improvements. The Unreal IRCd and vsftpd backdoor modules gained better check methods, native Meterpreter payloads, and verbose troubleshooting output. <\/p>\n<p>The SolarWinds exploit was improved to automatically select the correct SRVHOST value, and a check method was added to the MS17-010 scanner for better automation metadata. <\/p>\n<p>Additionally, the execution file was split to provide a more granular approach to handling different platforms and architectures. Finally, bug fixes were applied to the LDAP ESC and GraphQL Introspection scanners, eliminating crashes and false positives.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/metasploit-adds-new-modules-targeting-linux-rc4\/\">Metasploit Adds New Modules Targeting Linux RC4, BeyondTrust, and Registry Persistence<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Dhivya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/metasploit-adds-new-modules-targeting-linux-rc4\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Metasploit Adds New Modules Targeting Linux RC4, BeyondTrust, and Registry Persistence The latest Metasploit update, released on February 27, 2026, brings significant firepower to security professionals and penetration testers. The release introduces seven new modules, nine feature enhancements, and critical bug fixes. Standout additions include unauthenticated remote code execution (RCE) exploits for Ollama, BeyondTrust, and [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,416,131],"tags":[130],"class_list":["post-11017","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerabilities","category-vulnerability","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11017"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11017"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11017\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11017"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11017"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11017"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}