Security1 publisher3 min readPublished Updated
Thirteen new Metasploit modules close the patch window on SonicWall SMA1000, Ghost CMS and Langflow
Rapid7's latest wrap-up ships working exploit code for seven separately documented flaws, including an unauthenticated Joomla web shell and a Linux kernel LPE. Reprioritize this week, not next cycle.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Rapid7's Metasploit wrap-up post announced thirteen new modules.
- The wrap-up lists modules covering WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce issue, and the Fragnesia Linux kernel LPE (CVE-2026-46300).
- Metasploit also added new HTTP malleable profiles, MCP functionality and Linux multi fetch payloads, detailed in the Metasploit Framework 6.5 release post.
- The release adds brand-new AArch64 reverse-TCP shells, both inline and staged, described as confirming Windows on ARM as a first-class citizen.
- The Ray Dashboard Logs API Path Traversal module is an auxiliary module that leverages a path traversal vulnerability in Ray to list the contents of local directories; there is currently no CVE assigned and issuance is pending with MITRE.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Rapid7's latest Metasploit wrap-up landed thirteen new modules at once, covering WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce flaw and the Fragnesia Linux kernel local privilege escalation tracked as CVE-2026-46300 [1][2]. For anything on that list still unpatched in your estate, the practical exploitation cost just dropped to the price of running a framework that ships in every pentester's toolchain, which makes these tickets this week's work rather than next quarter's.
Three of the documented modules need no credentials at all [13]. The Joomla Content Editor module abuses CVE-2026-48907, where the profiles.import task fails to enforce authentication, letting an attacker import a crafted profile that gets written to disk as a PHP web shell; Rapid7 says every JCE version up to and including 2.9.99.4 is affected, and code execution follows when the tmp/ directory is directly reachable [11]. The Pterodactyl Panel module targets CVE-2025-49132 in versions before 1.11.11, chaining path traversal and arbitrary file creation through the locale.json endpoint into execution as the web server user [6]. The Langflow module is described simply as an unauthenticated RCE, CVE-2026-33017 [12].
The SonicWall entry is the one to escalate first if it applies. It exploits CVE-2026-15409, a server-side request forgery in the SMA1000 WorkPlace wsproxy service, and was written by Deral Heiland, Rapid7 Vulnerability Research and Ryan Emmons [7]. Fragnesia, CVE-2026-46300, is a page-cache replacement bug in the Linux kernel's XFRM (IPsec) subsystem shipped as a local module [8], which is the piece that turns any of the web-tier shells above into a full host compromise.
Two entries deserve care in ticketing. Ghost CMS requires valid admin or staff credentials, and works by uploading a malicious theme whose renderer evaluates untrusted JSONPath expressions through the {{#get}} helper [9]. Its identifier is inconsistent in Rapid7's own listing: the module path and description cite CVE-2026-29053 while the AttackerKB reference reads CVE-2026-22594 [10]. If you are matching advisories to assets by CVE string, that mismatch will cause a miss. The Ray Dashboard entry has no identifier at all, only an auxiliary module that uses a path traversal to list local directories, with CVE issuance described as pending with MITRE [5]. There is nothing to look up, so detection has to be behavioural.
The tooling changes matter less than the modules but are worth logging. The release added HTTP malleable profiles, MCP functionality and Linux multi fetch payloads alongside the 6.5 framework release [3], plus AArch64 reverse TCP shells in both inline and staged form for Windows on ARM [4]. Malleable HTTP profiles exist to make command and control traffic look like something else, so signature-based egress rules tuned to default Metasploit behaviour are the ones to review. If you have Snapdragon-class Windows endpoints outside your EDR coverage because the agent was never validated on ARM, that gap is now directly reachable [4].
Watch for the Ray Dashboard CVE assignment, since that is what most vulnerability management pipelines will wait on before creating work [5]. Watch whether the Ghost CMS identifier resolves to one number or two [10]. And note that the source wrap-up itemises detail for only seven of the thirteen modules [14]: the WordPress, OpenCATS and Pix-for-WooCommerce entries are named but not described in the material reviewed here [2], so check the module list directly before assuming your stack is clear.