Weekly Metasploit Update: Apache ActiveMQ RCE, Gogs Rebase RCE, and Windows Kernel Pointer Enum
2026-06-06T19:23:53Z•786a009c067a76d989c1b46bb399bc715c3df68362b18432f50506f91273759e
Apache ActiveMQCVE-2026-0826CVE-2026-3055CVE-2026-34197CVE-2026-43284CVE-2026-43500Citrix ADCDirty FragGogsHP Poly VVXJolokiaMetasploitNetScalerNtQuerySystemInformationRCEVoIP phonesWindows Kernelexploit moduleinfo leaklocal privilege escalationrebase RCEscannerstack-based buffer overflow
What happened
Rapid7 blog roundup and Metasploit update covering multiple new exploit and auxiliary modules plus vulnerability research. Key items: a Metasploit exploit for Apache ActiveMQ Jolokia addNetworkConnector (CVE-2026-34197) enabling remote code execution; Metasploit modules for two Linux local privilege escalation flaws dubbed “Dirty Frag” (CVE-2026-43284 and CVE-2026-43500); a Citrix ADC/NetScaler info‑leak scanner for CVE-2026-3055; a Gogs rebase-based RCE via specially named branches; Windows kernel pointer enumeration via NtQuerySystemInformation (useful for LPE chains); and Rapid7 disclosure/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- 786a009c067a76d989c1b46bb399bc715c3df68362b18432f50506f91273759e
- Enrichment time
- 2026-06-06T19:23:53Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.