EIP-2026-104121
PRE-CVEVNC Keyboard - Remote Code Execution (Metasploit)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-104121. PoCs published by Metasploit.
AI-analyzed exploit summary This Metasploit module exploits VNC servers by sending virtual keyboard inputs to execute commands. It supports Windows (via PowerShell or CMD) and Unix/Linux (via xterm) targets, leveraging VNC's keyboard event handling to achieve remote code execution.
Description
VNC Keyboard - Remote Code Execution (Metasploit)
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/37598
This Metasploit module exploits VNC servers by sending virtual keyboard inputs to execute commands. It supports Windows (via PowerShell or CMD) and Unix/Linux (via xterm) targets, leveraging VNC's keyboard event handling to achieve remote code execution.
Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target:
VNC Server (various versions)
Auth required
Prerequisites:
Network access to VNC server (default port 5900) · Valid VNC credentials or unauthenticated access
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026