Weekly Metasploit Update: Apache ActiveMQ RCE, Gogs Rebase RCE, and Windows Kernel Pointer Enum

2026-06-06T19:23:53Z786a009c067a76d989c1b46bb399bc715c3df68362b18432f50506f91273759e
Apache ActiveMQCVE-2026-0826CVE-2026-3055CVE-2026-34197CVE-2026-43284CVE-2026-43500Citrix ADCDirty FragGogsHP Poly VVXJolokiaMetasploitNetScalerNtQuerySystemInformationRCEVoIP phonesWindows Kernelexploit moduleinfo leaklocal privilege escalationrebase RCEscannerstack-based buffer overflow

What happened

Rapid7 blog roundup and Metasploit update covering multiple new exploit and auxiliary modules plus vulnerability research. Key items: a Metasploit exploit for Apache ActiveMQ Jolokia addNetworkConnector (CVE-2026-34197) enabling remote code execution; Metasploit modules for two Linux local privilege escalation flaws dubbed “Dirty Frag” (CVE-2026-43284 and CVE-2026-43500); a Citrix ADC/NetScaler info‑leak scanner for CVE-2026-3055; a Gogs rebase-based RCE via specially named branches; Windows kernel pointer enumeration via NtQuerySystemInformation (useful for LPE chains); and Rapid7 disclosure/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
786a009c067a76d989c1b46bb399bc715c3df68362b18432f50506f91273759e
Enrichment time
2026-06-06T19:23:53Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Weekly Metasploit Update: Apache ActiveMQ RCE, Gogs Rebase RCE, and Windows Kernel Pointer Enum · Baitaphish