#rapid7
MetasploitがPaperCut MF/NGのゼロデイRCE脆弱性に対するエクスプロイトを追加

Rapid7のMetasploit Frameworkに、 PaperCut MFおよびPaperCut NGに影響を与える、現在悪用されている一連の脆弱性を標的とするエクスプロイトモジュールが追加される予定です。この追加により、印刷管理サーバーに関わるセキュリテ...

提案されているモジュールは、攻撃者が脆弱なPaperCutアプリケーションサーバー上でリモートコード実行を実現するために悪用できる2つの脆弱性、CVE-2026-81578とCVE-2026-82078を対象としています。
Metasploit Adds Exploit for PaperCut MF/NG Zero-Day RCE Vulnerabilities
Actively exploited chain of vulnerabilities affecting PaperCut MF and PaperCut NG. This addition will provide public offensive tooling for a security emergency involving print management servers.
gbhackers.com
September 26, 2026 at 3:18 AM
CVE-2026-97228 - Rapid7 Bulk Export MCP — GraphQL Query Injection in Export Status Lookup
CVE ID : CVE-2026-97228

Published : Sept. 25, 2026, 10:25 a.m. | 34 minutes ago

Description : Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a GraphQL query injecti...
CVE-2026-97228 - Rapid7 Bulk Export MCP — GraphQL Query Injection in Export Status Lookup
Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a GraphQL query injection issue in the export-status component (`get_export_status` in `src/export_manager.py`), whereby the `export_id` value — an unvalidated MCP tool argument reaching the function via the `check_rapid7_export_status` and `download_rapid7_export` tools — is interpolated directly into the GraphQL query string. …
cvefeed.io
September 25, 2026 at 11:39 AM
🚨 EUVD-2026-86930
📊 2.7/10
🏢 Rapid7

📝 Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a GraphQL query injection issue in the export-status component (`get_export_status` in `src...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-86930

#cybersecurity #infosec #cve #euvd
September 25, 2026 at 11:01 AM
🟠 CVE-2026-89325 - High (7.8)

An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Wi...

https://www.thehackerwire.com/vulnerability/CVE-2026-89325/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
September 25, 2026 at 5:17 AM
🚨 EUVD-2026-86404
📊 7.8/10
🏢 Rapid7

📝 An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbit...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-86404

#cybersecurity #infosec #cve #euvd
September 24, 2026 at 8:02 PM
🚨 EUVD-2026-85881
📊 3.6/10
🏢 Rapid7

📝 Velociraptor's prefetch library contains an out of bound vulnerability which may cause a crash when parsing certain malformed prefetch files.

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85881

#cybersecurity #infosec #cve #euvd
September 24, 2026 at 3:02 PM
🚨 EUVD-2026-85882
📊 6.5/10
🏢 Rapid7

📝 Velociraptor contains a deadlock condition that may be triggered by authenticated users. The issue stems from a lock management bug in the user management ...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85882

#cybersecurity #infosec #cve #euvd
September 24, 2026 at 3:02 PM
🚨 EUVD-2026-85870
📊 9.9/10
🏢 Rapid7

📝 Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt. Although the f...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85870

#cybersecurity #infosec #cve #euvd
September 24, 2026 at 2:02 PM
CVE-2026-19072 - velociraptor
In Velociraptor, a user with the investigator role can change an internal setting that lets them run any query on the server, bypassing normal permission checks. This means…

Too many irrelevant or confusing CVEs? Use stackflag.com

#velociraptor #rapid7 #CVE #infosec
CVE-2026-19072: Velociraptor investigator can gain admin rights
In Velociraptor, a user with the investigator role can change an internal setting that lets them run any query on the server, bypassing normal permission.
stackflag.com
September 24, 2026 at 1:40 PM
CRITICAL: Rapid7 Velociraptor <0.77.2 has a privilege escalation flaw (CVE-2026-19072, CVSS 9.9). 'Investigator' users can gain admin by injecting VQL. Upgrade to 0.77.2+ ASAP. https://radar.offseq.com/threat/cve-2026-19072-cwe-1269-product-released-in-non-release-configuration-in-rapid7-velocira...
CVE-2026-19072: CWE-1269 Product released in Non-Release configuration in Rapid7
Velociraptor internally stores compiled VQL in the hunt object to optimize artifact execution. The internal field 'compiled_collector_args' was improperly exposed to user API calls, allowing users with minimal privileges ('investigator' rol
radar.offseq.com
September 24, 2026 at 1:30 PM
Security researchers at Rapid7 found malware disguised as HAProxy on two compromised systems.

Attackers who'd already breached the servers recompiled HAProxy with a hidden backdoor, because a healthy-looking load balancer draws less suspicion.
Read more: www.haproxy.com/blog/how-to-...
How to prove your HAProxy build is legitimate
Attackers trojanized HAProxy binaries on hosts they had already compromised. No CVE, no supply chain breach. Here are five habits for verifying the builds you run.
www.haproxy.com
September 21, 2026 at 3:55 PM
Citrix NetScalerの重要な認証バイパスに対する悪用が予想されるが、パッチが適用された。

CVE-2026-19490(CVSSスコア9.3)として追跡されているこの重大なバグは、代替パスを使用した認証バイパスとして説明されており、ゲートウェイ(SSL VPN、ICAプロキシ、CVPN、RDPプロキシ)またはAAA仮想サーバーとして構成されたNetScalerアプライアンスに影響を与えます。

サイバーセキュリティ企業のRapid7によると、この脆弱性は、ユーザーの操作なしに、遠隔地の認証されていない攻撃者によって悪用される可能性があるという。

Citrixの勧告によると...
Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler
Citrix has patched CVE-2026-19490, a critical-severity vulnerability in NetScaler leading to authentication bypass.
www.securityweek.com
September 20, 2026 at 2:16 AM
“They were buzzing [during Saturday's scrimmage]. It looks like they had fun. They were controlling the puck pretty good, especially in the O-zone; they had some chances...it was fun to watch.”

📰: https://bit.ly/4h07Ibg

#NHLBruins | @rapid7
September 19, 2026 at 10:30 PM
"There's no room for mistakes...we're gonna have to be dialed in for every game." -- @pastrnak96

More Day 1 reaction ➡️ https://bit.ly/4yABkBK

#NHLBruins | @rapid7
September 17, 2026 at 9:47 PM
Rapid7 Named Among Notable Vendors in Forrester MDR Landscape: Why the Future is Exposure

The strongest version of this narrative is that the cybersecurity industry is maturing; moving from "checkbox security" (having the tool) to "outcome security" (reducing actual risk). By integrating e…
huntaegis.com
September 17, 2026 at 3:40 PM
Rapid7 Product Push Highlights Turnaround at Piper Sandler Conference

Rapid7 emphasized its product strategy during the Piper Sandler conference. The company is focusing on a turna…

https://newsstocks.live/news/rapid7-product-push-highlights-turnaround-at-piper-sandler-conference #Finance #Markets
September 16, 2026 at 4:02 PM
🟢 Update: Rapid7 marked this resolved at 14:23 UTC.

Duration: 31m.
September 16, 2026 at 2:40 PM
⚠️ Rapid7 is reporting a Incident since 13:51 UTC

"Command Platform Dashboard Degradition"

Affects: User Interface, User Interface

Live timeline → https://pingoru.io/providers/rapid7/incidents/11061348

#Rapid7 #Rapid7Down
September 16, 2026 at 1:59 PM
サイバー攻撃、韓国のメディア・自動車セクターを標的に

韓国の自動車・メディア企業を狙った巧妙な攻撃により、あるスパイ活動グループが被害者のネットワークへのアクセスを獲得していたことが判明しました。一部のケースでは、2025年初頭からアクセスが継続していたとみられています。Rapid7が今週公開した分析によると、同社はこの攻撃を北朝鮮の高度持続的脅威(APT)グループによる
サイバー攻撃、韓国のメディア・自動車セクターを標的に
韓国の自動車・メディア企業を狙った巧妙な攻撃により、あるスパイ活動グループが被害者のネットワークへのアクセスを獲得していたことが判明しました。一部のケースでは、2025年初頭からアクセスが継続していたとみられています。Rapid7が今週公開した分析によると、同社はこの攻撃を北朝鮮の高度持続的脅威(APT)グループによる
blackhatnews.tokyo
September 16, 2026 at 1:10 AM
GitLab has patched CVE-2026-85706, a CVSSv3.1 10.0 path traversal vulnerability in the repository commits API that allows an unauthenticated user to read arbitrary files from GitLab CE and EE servers. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on September ..
Rapid7
www.rapid7.com
September 15, 2026 at 5:44 PM
Rapid7 just downgraded at JPMorgan
Reported Tuesday, Sep 15 - 4:50am EDT (TheFly subscription required to read more.)
thefly.com
September 15, 2026 at 8:50 AM