This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce, and for those who like their exploits closer to the bare-metal, the Fragnesia Linux kernel LPE (CVE-2026-46300). Metasploit also got the glow-up of the summer with the new http malleable profiles, MCP functionality and linux multi fetch payloads (more details on the official 6.5 release blog post!). Windows on ARM confirm to be the new first-class citizenship thanks to brand-new AArch64 reverse-TCP shells (both inline and staged), so your Snapdragon boxes can join the party too. Last but not least, an important message: Nyan Nyan Nyan Nyan Nyan Nyan.
Author: Richard Howe <rhowe425> Type: Auxiliary
Pull request: #21681 contributed by rmhowe425
Path: gather/ray_dashboard_logs_api_path_traversal
Description: This adds an auxiliary module that leverages a path traversal vulnerability in Ray to list the contents of local directories. There is currently no CVE assigned to this vulnerability. Issuance is pending with MITRE.
Authors: 0xtensho and jheysel-r7 Type: Exploit
Pull request: #21452 contributed by jheysel-r7
Path: linux/http/pterodactyl_locales_locale_json
AttackerKB reference: CVE-2025-49132 Description: This adds a module which exploits a vulnerability in Pterodactyl Panel before version 1.11.11 that allows unauthenticated remote code execution through improper handling of locale file operations. The vulnerability, CVE-2025-49132, exists in the locale.json endpoint which allows path traversal and arbitrary file creation. This combination of capabilities results in remote code execution in the context of the user running the web server.
Authors: Deral Heiland, Rapid7 Vulnerability Research, and Ryan Emmons
Type: Exploit
Pull request: #21678 contributed by dheiland-r7(https://github.com/dheiland-r7)
Path: linux/http/sonicwall_sma1000_wsproxy_rce
AttackerKB reference: CVE-2026-15409 Description: This adds a new exploit module for CVE-2026-15409, a Server-Side Request Forgery (SSRF) vulnerability in the SonicWall SMA1000 WorkPlace wsproxy service.
Authors: William Bowling and msutovsky-r7
Type: Exploit
Pull request: #21456 contributed by msutovsky-r7 Path: linux/local/cve_2026_46300_fragnesia
AttackerKB reference: CVE-2026-46300 Description: This adds a local module for the Fragnesia exploit which is a page-cache replacement vulnerability in the Linux kernel's XFRM (IPsec) subsystem, tracked as CVE-2026-46300.
Authors: Cristian-Alexandru Staicu and Maksim Rogov
Type: Exploit
Pull request: #21234 contributed by vognik Path: multi/http/ghostcms_auth_rce_cve_2026_29053
AttackerKB reference: CVE-2026-22594 Description: This adds an exploit module for Ghost CMS (CVE-2026-29053) that achieves remote code execution by up a malicious theme. Ghost's theme renderer evaluates untrusted JSONPath expressions through the {{#get}} helper, letting the module inject and trigger arbitrary code once a theme is uploaded and activated. You'll need valid admin or staff credentials to authenticate.
Authors: David Jardin, Uwe Flottemesch, and ispyispyispy
Type: Exploit
Pull request: #21615 contributed by 15py15py15py
Path: multi/http/joomla_com_jce_unauth_file_upload_rce
AttackerKB reference: CVE-2026-48907 Description: This adds a new exploit module for CVE-2026-48907, an unauthenticated arbitrary profile creation vulnerability in the JCE (Joomla Content Editor) extension for Joomla!. The profiles.import task fails to enforce authentication, letting an attacker import a crafted profile that is written to disk as a PHP web shell, resulting in remote code execution when the tmp/ directory is directly accessible. All JCE versions up to and including 2.9.99.4 are affected, and no credentials are required.
Authors: Diamorphine and Richard Howe
Type: Exploit
Pull request: #21700 contributed by rmhowe425 Path: multi/http/langflow_unauth_rce_cve_2026_33017
AttackerKB reference: CVE-2026-33017 Description: Adds a new multi/http/langflow_unauth_rce_cve_2026_33017 exploit module that exploits an unauth RCE vulnerability in the /api/v1/build_public_tmp/{flow_id}/flow endpoint in Langflow versions prior to 1.9.0.
Authors: Chocapikk and stlthr4k3r
Type: Exploit
Pull request: #21630 contributed by stlthr4k3r Path: multi/http/opencats_installer_rce
AttackerKB reference: CVE-2026-27760 Description: Adds an exploit module targeting CVE-2026-27760, a PHP code injection in OpenCATS.
Authors: Adam Kues, Crypto-Cat, TF1T, dtro, and haongo
Type: Exploit
Pull request: #21686 contributed by Crypto-Cat Path: multi/http/wp_batch_desync_rce
AttackerKB reference: CVE-2026-60137 Description: This adds an exploit module to target WP2Shell, an unauthenticated pre-auth remote code execution vulnerability affecting WordPress core versions 6.9.0–6.9.4 and 7.0.0–7.0.1. The module chains a REST API route confusion flaw (CVE-2026-63030) with an SQL injection (CVE-2026-60137) to elevate privileges, deploy a payload via a custom plugin, and execute a remote session.
Authors: Alexis Lafontaine and Maksim Rogov
Type: Exploit
Pull request: #21683 contributed by vognik Path: multi/http/wp_plugin_pix_unauth_rce_cve_2026_3891
AttackerKB reference: CVE-2026-3891 Description: Adds CVE-2026-3891 WordPress Unauthenticated RCE Exploit module targeting Pix for WooCommerce plugin.
Authors: OJ Reeves, Spencer McIntyre
Type: Payload (Single) Pull request: #21728 contributed by zeroSteiner Description: Adds support for a new MALLEABLEC2 option to Meterpreter HTTP(S) payloads. This feature enables users to load a standard profile into Meterpreter and change the shape of its HTTP(S) traffic. All Meterpreters, including Windows, Java, Python, PHP and Linux, have been updated with this functionality.
Author: vinicius-batistella
Type: Payload (Single)
Pull request: [#21589](https://www.google.com/search?q=https://github.com/rapid7/metasploit-framework/pull/21589) contributed by [vinicius-batistella](https://github.com/vinicius-batistella)
Path: windows/aarch64/shell_reverse_tcp
Description: Adds Windows on ARM (AArch64) reverse-TCP command-shell payload.
Author: vinicius-batistella
Type: Payload (Stager)
Pull request: [#21744](https://www.google.com/search?q=https://github.com/rapid7/metasploit-framework/pull/21744) contributed by [vinicius-batistella](https://github.com/vinicius-batistella)
Path: windows/aarch64/shell/reverse_tcp
Description: Adds Windows AARCH64 staged shell payloads.
You can find the latest Metasploit documentation on our docsite at docs.metasploit.com.
As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:
If you are a git user, you can clone the Metasploit Framework repo (master branch) for the latest. To install fresh without using git, you can use the open-source-only Nightly Installers or the commercial edition Metasploit Pro.