Vulnerabilities · 54 days ago

Metasploit 6.5 Lowers the Bar for Exploitation

Rapid7 shipped Metasploit 6.5 with 13 new exploit modules covering a string of already disclosed remote-code-execution flaws in WordPress, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, Pix-for-WooCommerce, and a Linux kernel local privilege escalation, CVE-2026-46300.

The practical change is packaging: these bugs are now one module away from use, alongside new HTTP malleable profiles, MCP support, Linux multi-fetch payloads, and AArch64 reverse-TCP shells. That does not create new flaws, but it does make public exploitation easier to adapt across more targets and environments, so unpatched internet-facing apps and appliances become simpler to test and operationalize.

For teams that run any of the covered products or the affected Linux kernel, the exposure is the same old patch gap — but with better attacker tooling behind it. The risk sits where public modules meet forgotten instances: systems that were already vulnerable now take less effort to turn into working shells.

CVE-2026-46300

NVD KEV

CVSS 7.8 HIGH: in the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() can attach paged frags from @from to @to. EPSS 2% (83rd percentile). Microsoft patch: CBL-Mariner Releases.

Timeline

Sources

1 source covering this story

Entities

Vendor digest: SonicWall

Part of the PlainSec briefing for 2026-08-15

Editions

Related stories