Metasploit Wrap Up: Belgian Waffles, Chocolates, and…Modules-Frites?
This wrap-up comes from the beautiful country of Belgium, where the Metasploit team is team-building and team-eating while we cheer on our very own teammates giving talks - shout-out to @jburgess-r7 who gave a wonderful talk about some of his 0day research.

If you're reading this and your self-hosted GitLab is running anything from 18.7 up to the fixed versions, please stop reading and go patch.
This wrap-up comes from the beautiful country of Belgium, where the Metasploit team is team-building and team-eating while we cheer on our very own teammates giving talks - shout-out to @jburgess-r7 who gave a wonderful talk about some of his 0day research.
Team building is a wonderful corporate ritual in which security researchers — people whose job is to break stuff and find ways into places they shouldn't be — are released into hotels full of questionable tech, and then everyone acts surprised by what happens next.
Description: This adds a new exploit module that detects and exploits an authenticated remote code execution vulnerability tracked as CVE-2026-18729 impacting Langflow versions 1.11.1 and below.
As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub: If you are a git user, you can clone the Metasploit Framework repo (master branch) for the latest.
Next, for anyone who has ever wanted to become the DNS server for an entire Windows network without the hassle of asking permission, we now have native mitm6-style DHCPv6 and IPv6 RA DNS takeover modules.
You can find the latest Metasploit documentation on our docsite at docs.metasploit.com .
To install fresh without using git, you can use the open-source-only Nightly Installers or the commercial edition Metasploit Pro
Description: This adds the auxiliary/spoof/ipv6/ipv6_ra_dns_takeover and auxiliary/spoof/dhcp/dhcpv6_dns_takeover modules to enable native IPv6 DNS-takeover coercion as part of a Kerberos authentication relay attack chain.
Description: Adds a module that exploits CVE-2026-85706, an unauthenticated local file read in the GitLab repository commits and files APIs.
What happened
If you're reading this and your self-hosted GitLab is running anything from 18.7 up to the fixed versions, please stop reading and go patch.
This wrap-up comes from the beautiful country of Belgium, where the Metasploit team is team-building and team-eating while we cheer on our very own teammates giving talks - shout-out to @jburgess-r7 who gave a wonderful talk about some of his 0day research.
What changed
Team building is a wonderful corporate ritual in which security researchers — people whose job is to break stuff and find ways into places they shouldn't be — are released into hotels full of questionable tech, and then everyone acts surprised by what happens next.
Description: This adds a new exploit module that detects and exploits an authenticated remote code execution vulnerability tracked as CVE-2026-18729 impacting Langflow versions 1.11.1 and below.
Who is affected
As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub: If you are a git user, you can clone the Metasploit Framework repo (master branch) for the latest.
Next, for anyone who has ever wanted to become the DNS server for an entire Windows network without the hassle of asking permission, we now have native mitm6-style DHCPv6 and IPv6 RA DNS takeover modules.
Why it matters
You can find the latest Metasploit documentation on our docsite at docs.metasploit.com .
To install fresh without using git, you can use the open-source-only Nightly Installers or the commercial edition Metasploit Pro
Technical details
Description: This adds the auxiliary/spoof/ipv6/ipv6_ra_dns_takeover and auxiliary/spoof/dhcp/dhcpv6_dns_takeover modules to enable native IPv6 DNS-takeover coercion as part of a Kerberos authentication relay attack chain.
Description: Adds a module that exploits CVE-2026-85706, an unauthenticated local file read in the GitLab repository commits and files APIs.
The issue affects GitLab CE and EE versions from 18.7 before 19.1.8 , 19.2 before 19.2.6 , and 19.3 before 19.3.2 .
Response
Remember that IPv6 stack you never configured, never use, and definitely never disabled?
Attribution
Rapid7: This wrap-up comes from the beautiful country of Belgium, where the Metasploit team is team-building and team-eating while we cheer on our very own teammates giving talks - shout-out to @jburgess-r7 who gave a wonderful talk about some of his 0day research.
What to watch next
Watch for updated vendor guidance and fixed-version details.