Weekly Metasploit Update: Apache ActiveMQ RCE, Gogs Rebase RCE, and Windows Kernel Pointer Enum

2026-06-07T07:23:45Z05ee354bc9b975da009334fe4bddc66357e401f94af3691b9ab9db18cbf071b0
apache-activemqbranch-namingcitrix-netscalerdirty-fragexploit-modulegogshp-polyinfo-leakjolokiakernel-pointer-enumerationlinux-lpelocal-privilege-escalationmetasploitntquerysysteminformationrceremote-code-executionscannervoip

What happened

Rapid7 posts detail a Metasploit update and multiple vendor advisories. New Metasploit modules include an Apache ActiveMQ Jolokia RCE exploit targeting CVE-2026-34197, modules for Dirty Frag Linux local privilege escalations (CVE-2026-43284 and CVE-2026-43500), a Citrix ADC (NetScaler) CVE-2026-3055 scanner (memory/info-leak), a Windows kernel pointer enumeration post-module (NtQuerySystemInformation), and other auxiliary scanners. Rapid7 also published a critical unauthenticated stack buffer overflow affecting HP/Poly VVX and Trio VoIP phones (CVE-2026-0826) enabling remote root RCE when ICE/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
05ee354bc9b975da009334fe4bddc66357e401f94af3691b9ab9db18cbf071b0
Enrichment time
2026-06-07T07:23:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.