Metasploit Wrap Up: Belgian Waffles, Chocolates, and…Modules-Frites?
Metasploit 6.5.5 adds modules for in-the-wild GitLab file read, IPv6 DNS takeover, and Langflow RCE.
Rapid7's Metasploit wrap-up for Framework 6.5.5 highlights an unauthenticated GitLab arbitrary file read, CVE-2026-85706, which the team says is exploited in the wild. It affects GitLab CE and EE from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. New auxiliary modules implement mitm6-style DHCPv6 and IPv6 router-advertisement DNS takeover (CVE-2026-20929) for Kerberos relay against Windows. An exploit module targets authenticated RCE in Langflow 1.11.1 and earlier via custom components (CVE-2026-18729), plus a Kate plugin persistence module.
75