Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!

Imported from official source

Cybersecurity Classified by Officially

Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!

Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!

This release has something for everyone: scanner modules, payloads, and exploits. This release’s scanners cover Drupal, PanOS, WordPress, and SCADA; this release’s exploits cover Tenable, Flowise, CheckPoint, Langflow, Ruby, and SPIP.

Forgejo Arbitrary File Read via Org-mode Include

Pull request: #21778 contributed by jvoisin

Path: gather/forgejo_orgmode_fileread_cve_2026_59774

Description: Adds module targeting CVE-2026-59774, an arbitrary file read in Forgejo 7.0 through 15.0.5 and 16.0.0–16.0.1.

Wordpress Planyo Online Reservation System Arbitrary File Read (CVE-2026-3576)

Authors: Balachandar Gowrisankar and sinn3r [email protected]

Pull request: #21769 contributed by anirbala98

Path: gather/wp_planyo_lfi_cve_2026_3576

Description: This adds a module for, CVE-2026-3576, a local file inclusion vulnerability via server side request forgery in WordPress's Planyo Online Reservation System plugin (versions < 3.1). The plugin's AJAX proxy ulap.php does not validate the scheme of URLs supplied to it. This allows unauthenticated attackers to supply file:// URLs to ulap.php and retrieve any arbitrary local file contents from the target.

Concrete CMS Unauthenticated File Usage Disclosure

Pull request: #21695 contributed by zoomdbz

Path: scanner/http/concrete_cms_file_usage_disclosure

Description: Adds an auxiliary scanner module for CVE-2026-6826: Concrete CMS 9.x before 9.5.1 exposes the file usage dialog controller at /ccm/system/dialogs/file/usage/<fID> without a view permission check.

Drupal Core PostgreSQL EntityQuery SQL Injection

Pull request: #21765 contributed by JohannesLks

Path: scanner/http/drupal_pgsql_entityquery_sqli

This is an extract. The publication continues at the source.

Read the original at the source: https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-payloads-exploits-scanners

Officially imported this from Rapid7’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Rapid7 — imported from official source
Official source
https://blog.rapid7.com/rss/ RSS
Imported
September 18, 2026 11:35
Versions
1 recorded
Identity
blt526bc61553e28979

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.