VulnSea

rapid7 has 8 CVEs on record between 2025 and 2026. Disclosure cadence is accelerating: 7 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 7. The median CVSS is 7.3 (high), with 2 rated critical. None have a confirmed exploitation report. Most affected products: Velociraptor (6), Insight Agent (1), Platform (1).

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
7.3
Publish → KEV
—
Last 90 days
7 prev 0

Products

  • Velociraptor 6
  • Insight Agent 1
  • Platform 1
8
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

rapid7 vulnerabilities

CVEs affecting rapid7, newest first. Open any entry for full detail, references, and exploit status.

8 CVEsRSS

CVE-2026-97228Low· 2.7
6d ago

Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a GraphQL query injection issue in the export-status component (`get_export_status` in `src/export_manager.py`), whereby the `export_id` value — an unvalidated MCP tool argu…

Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a GraphQL query injection issue in the export-status component (`get_export_status` in `src/export_manager.py`), whereby the `export_id` value — an unvalidated MCP tool argu…

▾ SunlitRapid7 · PlatformEPSS 0.25%via NVD
CVE-2026-89325High· 7.8
1w ago

An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbitrary code as SYSTEM via a planted executable resolved from the machine PATH. Asse…

An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbitrary code as SYSTEM via a planted executable resolved from the machine PATH. Asse…

▾ TwilightRapid7 · Insight AgentEPSS 0.13%via NVD
CVE-2026-77798Medium· 6.5
1w ago

Velociraptor contains a deadlock condition that may be triggered by authenticated users

Velociraptor contains a deadlock condition that may be triggered by authenticated users. The issue stems from a lock management bug in the user management module.

▾ SunlitRapid7 · VelociraptorEPSS 0.20%via NVD
CVE-2026-77797Low· 3.6
1w ago

Velociraptor's prefetch library contains an out of bound vulnerability which may cause a crash when parsing certain malformed prefetch files.

Velociraptor's prefetch library contains an out of bound vulnerability which may cause a crash when parsing certain malformed prefetch files.

▾ SunlitRapid7 · VelociraptorEPSS 0.10%via NVD
CVE-2026-19072Critical· 9.9
1w ago

Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt

Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt. Although the field "compiled_collector_args" is an internal field, Velociraptor allowed the fiel…

▾ MidnightRapid7 · VelociraptorEPSS 0.40%via NVD
CVE-2026-19584High· 7.7
3w ago

Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature

Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a mali…

▾ TwilightRapid7 · VelociraptorEPSS 0.19%via NVD
CVE-2026-19583Critical· 9.9
3w ago

Velociraptor Required Permissions bypass by using client monitoring queries

Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. Howe…

▾ MidnightRapid7 · VelociraptorEPSS 0.60%via CVEORG
CVE-2025-14728Medium· 6.8
9mo ago

Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue client to upload a file which is written outside the datastore directory

Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue client to upload a file which is written outside the datastore directory. Velociraptor is normally only allowed to write …

▾ Sunlitrapid7 · velociraptorEPSS 0.56%via NVD
rapid7 vulnerabilities (CVEs) · VulnSea