Skip to content

Rapid7 vulnerabilities

2 CVEs tracked

Rapid7 appears in recent reporting both for vulnerabilities in its own products and for threat discoveries. The company exposed an AI-assisted phishing toolkit (WebDAV malware campaign) via an open server and is also sunsetting the public 'AttackerKB' platform to unify its vulnerability intelligence. A critical vulnerability affecting its own products has been identified: **CVE-2026-14172**, which allows a local low-privileged user to achieve code execution as `root`/`SYSTEM` due to improper file ownership validation during authenticated scans in InsightVM, Nexpose, and Insight Agent. Defenders should prioritize applying the available updates for the Scan Engine and Insight Agent to patch this vulnerability and reconfigure intelligence feeds following the AttackerKB shutdown.

Azərbaycanca: Rapid7 son hesabatlarda həm öz məhsullarındakı zəifliklər, həm də kəşf etdiyi təhlükələr kontekstində görünür. Şirkət açıq qalmış server vasitəsilə aşkarlanan AI dəstəkli fişinq alət dəsti (WebDAV zərərli proqram kampaniyası) barədə məlumat yayımlayıb, eyni zamanda 'AttackerKB' platformasını bağlayaraq zəiflik kəşfiyyatını birləşdirməyə çalışır. Təchizatçı kimi öz məhsulları üçün kritik bir zəiflik də qeydə alınıb: **CVE-2026-14172** (InsightVM/Nexpose/Insight Agent-də autentifikasiya edilmiş skan zamanı fayl sahibliyini yoxlamadan tapılmış icra olunan faylların işə salınması), bu da lokal az imtiyazlı istifadəçiyə `root`/`SYSTEM` səviyyəsində kod icrası imkanı verir. Müdafiəçilər ən qısa zamanda Scan Engine və Insight Agent üçün təqdim olunan yeniləmələri tətbiq etməli, həmçinin bu kəşfiyyat platformasının bağlanması ilə bağlı zəiflik mənbələrini yenidən konfiqurasiya etməlidirlər.

This vendor's CVEs2

This hub is built from skopnix's own reporting on Rapid7: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.