Rapid7 has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 8.8 (high), with 1 rated critical.
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.8
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
Weakness classes
Products
- Velociraptor 2
2
Total CVEs
1
Critical
0
CISA KEV
0
Exploited
Rapid7 vulnerabilities
CVEs affecting Rapid7, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-19584High· 7.7Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature
Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a mali…
▾ TwilightRapid7 · VelociraptorEPSS 0.19%via NVD
CVE-2026-19583Critical· 9.9Velociraptor Required Permissions bypass by using client monitoring queries
Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. Howe…
▾ MidnightRapid7 · VelociraptorEPSS 0.60%via CVEORG