Weekly Metasploit Update: Apache ActiveMQ RCE, Gogs Rebase RCE, and Windows Kernel Pointer Enum

2026-06-06T07:23:48Ze8af28e2a104bf104dc4ca2413167f6d322fe993eeac4f1216e7ea027219b9ff
apache-activemqcitrix-netscalerdirty-fragexploit-modulegogshp-polyinfo-leakjolokiakernel-pointerslocal-privilege-escalationmetasploitntquerysysteminformationremote-code-executionvoip-phones

What happened

Rapid7 published multiple posts covering new Metasploit modules and vulnerability research. New/updated Metasploit content includes an Apache ActiveMQ Jolokia RCE exploit targeting CVE-2026-34197, scanners/modules for Citrix ADC (CVE-2026-3055), and two Linux local privilege escalation issues grouped as “Dirty Frag” (CVE-2026-43284 and CVE-2026-43500). Rapid7 Labs disclosed CVE-2026-0826, a critical unauthenticated stack-based buffer overflow in HP/Poly VVX and Trio VoIP phones enabling remote root RCE when ICE is enabled. Other coverage highlights a Gogs rebase/name-based RCE, kernel pointer/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
e8af28e2a104bf104dc4ca2413167f6d322fe993eeac4f1216e7ea027219b9ff
Enrichment time
2026-06-06T07:23:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.