Metasploit Wrap Up: Lot of summer shells and fit http profiles Rapid7's Metasploit Framework 6.5 release adds 13 new modules, including exploits for WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, Pix-for-WooCommerce, and the Fragnesia Linux kernel LPE (CVE-2026-46300). The update also introduces HTTP malleable profiles, MCP functionality, Linux multi fetch payloads, and AArch64 reverse-TCP shells for Windows on ARM. Notable vulnerabilities addressed include CVE-2025-49132 in Pterodactyl Panel before 1.11.11 and CVE-2026-15409 in SonicWall SMA1000 WorkPlace wsproxy. This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce, and for those who like their exploits closer to the bare-metal, the Fragnesia Linux kernel LPE CVE-2026-46300 . Metasploit also got the glow-up of the summer with the new http malleable profiles, MCP functionality and linux multi fetch payloads more details on the official 6.5 release blog post https://www.rapid7.com/blog/post/pt-metasploit-framework-6-5-released/ . Windows on ARM confirm to be the new first-class citizenship thanks to brand-new AArch64 reverse-TCP shells both inline and staged , so your Snapdragon boxes can join the party too. Last but not least, an important message: Nyan Nyan Nyan Nyan Nyan Nyan. Author: Richard Howe