CVE Tools

Metasploit Wrap Up: Lot of summer shells and fit http profiles

Rapid7 BlogBy Diego Ledda8 min read

PoC publicMetasploitWordPress WP2Shell

Our summary

Rapid7's Metasploit framework has released a major update featuring thirteen new modules that provide working proof-of-concepts for recent vulnerabilities in popular platforms such as WordPress, Ghost CMS, Joomla, and the Linux kernel. Notable additions include exploit paths for CVE-2026-60137 in WordPress core, unauthenticated remote code execution in Joomla JCE via CVE-2026-48907, and a local privilege escalation module for the Fragnesia Linux kernel tracked as CVE-2026-46300. This release also introduces new AArch64 payloads for Windows on ARM and enhanced HTTP malleable profiles, significantly expanding the offensive capabilities available to security teams.

Read at Rapid7 Blog

Below is the opening; the full story is at Rapid7 Blog.

From Rapid7 Blog

This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce, and for those who like their exploits closer to the bare-metal, the Fragnesia Linux kernel LPE (CVE-2026-46300). Metasploit also got the glow-up of the summer with the new http malleable profiles, MCP functionality and linux multi fetch payloads (more details on the \official 6.5 release blog post!). Windows on ARM confirm to be the new first-class citizenship thanks to brand-new AArch64 reverse-TCP shells (both inline and staged), so your Snapdragon boxes can join the party too. Last but not least, an important message: *Nyan Nyan Nyan Nyan Nyan Nyan.*…

Continue at Rapid7 Blog

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store