Weekly Metasploit Update: Apache ActiveMQ RCE, Gogs Rebase RCE, and Windows Kernel Pointer Enum

2026-06-08T07:23:47Zfc720f585b145a2731c8be26439a3b6af4bf365856977a1f672d485816c37d11
Apache ActiveMQCitrix NetScalerGogs RCEJolokiaLinux LPEMetasploitNtQuerySystemInformationRCEVoIPbuffer overflowinfo-leakkernel pointer enumerationlocal privilege escalationremote code executionunauthenticated

What happened

Rapid7 blog roundup and advisories covering multiple vulnerability disclosures and Metasploit additions. Highlights include a new Metasploit exploit for Apache ActiveMQ Jolokia RCE (CVE-2026-34197), Metasploit modules for recent Linux local privilege escalations (Dirty Frag: CVE-2026-43284 and CVE-2026-43500) and a Citrix ADC (NetScaler) info-leak scanner (CVE-2026-3055). Rapid7 Labs disclosed a critical unauthenticated stack-buffer-overflow in HP Poly VVX/Trio VoIP phones (CVE-2026-0826) that allows remote root RCE when ICE is enabled; follow-up analysis discusses risk to voice infrastructure

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
fc720f585b145a2731c8be26439a3b6af4bf365856977a1f672d485816c37d11
Enrichment time
2026-06-08T07:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.