Rapid7 maintains a modestly sized but highly prominent portfolio of security assessment, penetration-testing, and endpoint-monitoring products including Nexpose, Metasploit, Velociraptor, InsightVM, and the Insight Agent platform. The vendor's vulnerability profile reflects the attack surface of web-facing consoles and agent-based infrastructure: durable weakness classes center on cross-site scripting, path traversal, untrusted search paths, CSRF, and session-management flaws that are endemic to authentication boundaries and file-system interaction in security tools. A moderate share of the vendor's disclosures acquire public exploit code, making timely patching operationally important for environments where these products are internet-reachable or integrated with critical workflows. Defenders should monitor Rapid7's advisories closely, particularly for the widely deployed Insight Agent and InsightVM scanning platform, and prioritize remediation of network-facing instances; live severity and exploitation data are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rapid7, Inc. over time
Of all the CVEs published by Rapid7, Inc. as a CNA, 34.2% affect products that Rapid7, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Rapid7, Inc., 96.8% are self-published by Rapid7, Inc. as a CNA.
Signals from CVEs in this vendor scope (95 CVEs).
95 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7384HIGH Rapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish a file that would execute arbitrary commands on a victim's m | Oct 29, 2020 | 7.8 | 61 | NO | YES |
CVE-2019-5645HIGH By sending a specially crafted HTTP GET request to a listening Rapid7 Metasploit HTTP handler, an attacker can register an arbitrary regular expression. When evaluated, this malici | Sep 1, 2020 | 7.5 | 59 | NO | YES |
CVE-2017-5264HIGH Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrative web application, and are susceptible t | Dec 14, 2017 | 8.8 | 39 | NO | YES |
CVE-2026-8666CRITICAL OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute arbitrary OS commands via the hos | Jun 25, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-8665CRITICAL OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expr | Jun 25, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-8660CRITICAL OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host parameter | Jun 25, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-8663HIGH OS Command Injection vulnerability in Rapid7 InsightConnect RPM Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the repo, key, or name parameter | Jun 25, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-8592CRITICAL OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text o | Jun 25, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-8658HIGH OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the options or filter parame | Jun 25, 2026 | 8.8 | 36 | NO | NO |
CVE-2026-8664HIGH OS Command Injection vulnerability in Rapid7 InsightConnect Finger Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the user or host parameters d | Jun 25, 2026 | 8.8 | 35 | NO | NO |
Signals from CVEs in this vendor scope (95 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rapid7, Inc..
Media articles that mention a CVE ID that affects a product developed by Rapid7, Inc. — matched by CVE ID, not by vendor name.