Metasploit 6.5 Lowers the Bar for Exploitation

Rapid7 shipped Metasploit 6.5 with 13 new exploit modules covering a string of already disclosed remote-code-execution flaws in WordPress, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, Pix-for-WooCommerce, and a Linux kernel local privilege escalation, CVE-2026-46300. The practical change is packaging: these bugs are now one module away from use, alongside new HTTP malleable profiles, MCP support, Linux multi-fetch payloads, and AArch64 reverse-TCP shells. That does not create new flaws, but it does make public exploitation easier to adapt across more targets and environments, so unpatched internet-facing apps and appliances become simpler to test and operationalize. For teams that run any of the covered products or the affected Linux kernel, the exposure is the same old patch gap — but with better attacker tooling behind it. The risk sits where public modules meet forgotten instances: systems that were already vulnerable now take less effort to turn into working shells.

Sources