Security1 distinct publisher3 min readUpdated
Rapid7's latest wrap-up ships working exploit code for seven separately documented flaws, including an unauthenticated Joomla web shell and a Linux kernel LPE. Reprioritize this week, not next cycle.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Rapid7's latest Metasploit wrap-up landed thirteen new modules at once, covering WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce flaw and the Fragnesia Linux kernel local privilege escalation tracked as CVE-2026-46300 [1][2]. For anything on that list still unpatched in your estate, the practical exploitation cost just dropped to the price of running a framework that ships in every pentester's toolchain, which makes these tickets this week's work rather than next quarter's.
Three of the documented modules need no credentials at all [13]. The Joomla Content Editor module abuses CVE-2026-48907, where the profiles.import task fails to enforce authentication, letting an attacker import a crafted profile that gets written to disk as a PHP web shell; Rapid7 says every JCE version up to and including 2.9.99.4 is affected, and code execution follows when the tmp/ directory is directly reachable [11]. The Pterodactyl Panel module targets CVE-2025-49132 in versions before 1.11.11, chaining path traversal and arbitrary file creation through the locale.json endpoint into execution as the web server user [6]. The Langflow module is described simply as an unauthenticated RCE, CVE-2026-33017 [12].
The SonicWall entry is the one to escalate first if it applies. It exploits CVE-2026-15409, a server-side request forgery in the SMA1000 WorkPlace wsproxy service, and was written by Deral Heiland, Rapid7 Vulnerability Research and Ryan Emmons [7]. Fragnesia, CVE-2026-46300, is a page-cache replacement bug in the Linux kernel's XFRM (IPsec) subsystem shipped as a local module [8], which is the piece that turns any of the web-tier shells above into a full host compromise.
Two entries deserve care in ticketing. Ghost CMS requires valid admin or staff credentials, and works by uploading a malicious theme whose renderer evaluates untrusted JSONPath expressions through the {{#get}} helper [9]. Its identifier is inconsistent in Rapid7's own listing: the module path and description cite CVE-2026-29053 while the AttackerKB reference reads CVE-2026-22594 [10]. If you are matching advisories to assets by CVE string, that mismatch will cause a miss. The Ray Dashboard entry has no identifier at all, only an auxiliary module that uses a path traversal to list local directories, with CVE issuance described as pending with MITRE [5]. There is nothing to look up, so detection has to be behavioural.
The tooling changes matter less than the modules but are worth logging. The release added HTTP malleable profiles, MCP functionality and Linux multi fetch payloads alongside the 6.5 framework release [3], plus AArch64 reverse TCP shells in both inline and staged form for Windows on ARM [4]. Malleable HTTP profiles exist to make command and control traffic look like something else, so signature-based egress rules tuned to default Metasploit behaviour are the ones to review. If you have Snapdragon-class Windows endpoints outside your EDR coverage because the agent was never validated on ARM, that gap is now directly reachable [4].
Watch for the Ray Dashboard CVE assignment, since that is what most vulnerability management pipelines will wait on before creating work [5]. Watch whether the Ghost CMS identifier resolves to one number or two [10]. And note that the source wrap-up itemises detail for only seven of the thirteen modules [14]: the WordPress, OpenCATS and Pix-for-WooCommerce entries are named but not described in the material reviewed here [2], so check the module list directly before assuming your stack is clear.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Rapid7's Metasploit wrap-up post announced thirteen new modules.
The wrap-up lists modules covering WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce issue, and the Fragnesia Linux kernel LPE (CVE-2026-46300).
Metasploit also added new HTTP malleable profiles, MCP functionality and Linux multi fetch payloads, detailed in the Metasploit Framework 6.5 release post.
The release adds brand-new AArch64 reverse-TCP shells, both inline and staged, described as confirming Windows on ARM as a first-class citizen.
The Ray Dashboard Logs API Path Traversal module is an auxiliary module that leverages a path traversal vulnerability in Ray to list the contents of local directories; there is currently no CVE assigned and issuance is pending with MITRE.
The Pterodactyl Panel module exploits CVE-2025-49132 in versions before 1.11.11, an unauthenticated remote code execution issue in the locale.json endpoint that combines path traversal and arbitrary file creation to execute code as the user running the web server.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary release notes, single-sourced
Every substantive claim traces to first-party release documentation with unusually checkable specifics: module paths, pull request numbers, author handles, affected version ranges and AttackerKB CVE references. That is strong evidence that the exploit code exists and does what is described. It is capped by having exactly one source, no independent confirmation, and two internal defects, the Ghost CMS listing citing CVE-2026-29053 and CVE-2026-22594 for the same module and the Ray issue carrying no CVE at all.
Code merged and shipping; downstream uptake unknown
Adoption is real but one-sided. The modules are merged pull requests inside the mainline Metasploit Framework, which is a widely deployed offensive and validation toolkit, so availability to practitioners is concrete rather than announced intent, and the 6.5 framework capabilities ship alongside. What is entirely absent is the other half: no download, run, customer or scan telemetry, no evidence of exploitation in the wild, and no data on how many affected SonicWall, Joomla, Ghost, Langflow or Ray installations exist or have patched.
Urgency framing outruns the supplied evidence
The underlying facts are solid and materially serious, so this is mild overstatement rather than vapour. But the framing that the release 'closes the patch window' and requires reprioritisation this week implies active exploitation pressure and exposure scale that no supplied source establishes; the post documents module availability only. Two derived counts in the ledger also overstate scarcity of detail in the opposite direction, claiming three unauthenticated modules and seven itemised entries when the body shows at least five and at least ten, which signals summarisation drift rather than vendor exaggeration.
Vendor documenting its own tool and its own research
The single source is Rapid7 publishing about Metasploit, which Rapid7 owns and which anchors its security-research brand and commercial exposure-management positioning. One highlighted module exploits a vulnerability credited to Rapid7 Vulnerability Research itself, aligning research credit with product promotion. The offsetting factor is format: release notes that credit external contributors by handle and pull request are verifiable and leave little room for selective framing about what shipped.
High confidence in the artefacts, low in the consequences
Confidence is high that these modules and CVEs exist as described, because release notes with pull request numbers and module paths are self-verifying artefacts. It is much lower on what follows: with one vendor source, no independent corroboration, no exploitation or exposure telemetry, an unresolved CVE conflict in the Ghost entry, a missing identifier for the Ray flaw, and a truncated capture, the operational severity and reach implied by the story remain unmeasured.
product
CISA gives federal agencies three days to patch Ray, the framework under your ML pipelines1 distinct publisher
security
CVE-2025-62593: A Ray Developer's Browser Is Now the Attack Surface1 distinct publisher
security
A North Korean IT worker got hired by a federal agency. Vetting is a security control now.1 distinct publisher
science
OX Security says MCP command execution is a design choice, so server owners own the risk1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 14, 2026