Metasploit Adds Forgejo and Planyo Attack Modules

Rapid7 shipped a Metasploit update with 16 new modules, including public modules for Forgejo CVE-2026-59774 and WordPress Planyo CVE-2026-3576. The same release also adds scanners and exploit modules for other web apps, including Drupal, PAN-OS, Langflow, Flowise, CheckPoint, Tenable, SPIP, Ruby, and SCADA targets. The practical change is reach. Metasploit turns research findings into off-the-shelf checks and exploits, so operators of exposed self-hosted apps now face a much lower barrier for mass probing and opportunistic exploitation, even where no custom attacker code exists. That shifts these bugs from lab-interest to routine tooling in the hands of anyone who already runs the framework. For teams with internet-facing Forgejo instances or WordPress sites using Planyo, the exposure is no longer just whether a flaw exists but whether public tooling can find it quickly. The report does not show active exploitation here, but it does show how fast a newly published weakness can become broadly usable attacker infrastructure.

Part of the PlainSec briefing for 2026-08-29

Every edition of this story: Metasploit Adds Forgejo and Planyo Attack Modules

CVEs

Sources