Metasploit Framework 6.5 Bolsters Attack Arsenal with 13 New Modules, Enhanced HTTP Profiles
Rapid7's Metasploit Framework 6.5 release introduces 13 new modules, including exploits for critical vulnerabilities in popular software like WordPress, Joomla, and SonicWall, alongside significant enhancements to HTTP malleable profiles and Windows on ARM support.

The latest iteration of the Metasploit Framework, version 6.5, has been released by Rapid7, packing a significant punch with the addition of thirteen new modules designed to aid penetration testers and security researchers. This update focuses on expanding the framework's capabilities across various platforms and applications, addressing a range of vulnerabilities from remote code execution to local privilege escalation.
The new modules cover a diverse set of targets, including popular content management systems and enterprise software. Among the notable additions are exploits for WordPress WP2Shell, Ghost CMS (CVE-2026-29053), Joomla JCE (CVE-2026-48907), Pterodactyl Panel (CVE-2025-49132), and SonicWall SMA1000 (CVE-2026-15409). These modules allow security professionals to test the resilience of these systems against known exploits, identify potential weaknesses, and validate patch deployments.
Beyond web applications, Metasploit 6.5 also introduces a critical local privilege escalation (LPE) exploit for the Linux kernel, specifically targeting the Fragnesia vulnerability (CVE-2026-46300). This addition enhances the framework's ability to test for kernel-level compromises, a crucial aspect of comprehensive security assessments. The inclusion of such low-level exploits underscores the ongoing need for robust kernel security and timely patching.
Significant improvements have also been made to Metasploit's networking and payload capabilities. The framework now boasts enhanced HTTP malleable profiles, offering more sophisticated ways to disguise network traffic and evade detection. Furthermore, the release introduces support for AArch64 reverse-TCP shells on Windows on ARM, effectively bringing Windows on ARM devices into the fold for payload delivery and command and control, expanding the reach of penetration testing operations.
Several specific modules highlight the breadth of this update. The Ray Dashboard Logs API Path Traversal module allows for the enumeration of local directories, while the Pterodactyl Panel exploit targets an improper handling of locale file operations leading to RCE. The SonicWall SMA1000 module addresses an SSRF vulnerability, and the Joomla JCE exploit leverages an unauthenticated file upload flaw for RCE. The WordPress WP2Shell exploit chains a REST API route confusion with SQL injection for RCE, and a separate module targets an unauthenticated RCE in the Pix for WooCommerce plugin.
Other notable additions include exploits for Langflow's unauthenticated RCE, OpenCATS' installer PHP code injection, and a module for Ghost CMS that achieves RCE via malicious theme uploads. Each of these modules is meticulously crafted to replicate real-world attack vectors, providing invaluable tools for defensive security teams to understand and counter emerging threats.
The release also emphasizes the ongoing evolution of exploit development, with contributions from a wide array of security researchers. This collaborative effort ensures that Metasploit remains a cutting-edge tool, constantly updated with the latest vulnerability research and exploitation techniques. The framework's commitment to supporting diverse architectures and platforms, as demonstrated by the Windows on ARM support, further solidifies its position as an indispensable resource in the cybersecurity landscape.
In summary, Metasploit Framework 6.5 represents a substantial advancement, equipping security professionals with a more potent and versatile toolkit. The influx of new exploits, coupled with enhancements to core functionalities like HTTP profiles and cross-architecture support, ensures that Metasploit continues to be a vital instrument for vulnerability assessment, penetration testing, and overall cybersecurity resilience.