Rapid7 Research
rapid7-research · B · active
Rapid7 vuln and incident research; Metasploit project; weekly Metasploit Wrap-Up. RSS at https://www.rapid7.com/rss.xml. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → feed https://www.rapid7.com/rss.xml 5 (feed carries full HTML body incl. CVE detail; per-post URL drill optional). AVOID: Don't WebFetch the /blog/ landing page — the rss.xml feed already returns full post bodies with CVE IDs and module detail.. | 2026-06-30: a sub-agent hit HTTP 404 on https://www.rapid7.com/blog/feed/ — that is the WRONG endpoint. Correct feed is https://www.rapid7.com/rss.xml (already documented above). Source healthy; no demotion. | 2026-07-05 admiralty audit: B — original vendor vuln/incident research + Metasploit wrap-ups. Live and fresh (daily/weekly). Active retained; use rss.xml (not /blog/feed/).
Cited in 30 entries
Citation cadence
Citation days per ISO week (13 weeks of coverage span, total 19).
- Every authentication bypass disclosed this week came from code accepting an attacker-supplied value as proof of identity — the check ran, it just validated the wrong thing2026-08-02
- The exploited surface this week was the management plane itself — VeloCloud Orchestrator, Secure FMC, Check Point SmartConsole, FortiOS SSL-VPN and exposed BMCs, and on several of them what the attacker obtained outlives the upgrade2026-08-02
- CVE-2026-66066 — Ruby on Rails Active Storage: an unauthenticated image upload reaches arbitrary file read through libvips' unfuzzed loaders, exposing every application secret (CVSS 4.0 9.5)2026-07-31
- CVE-2026-16232 root cause — Check Point SmartConsole accepted a caller-supplied SIC distinguished name as identity, and the exploitable Trusted Clients setting was the default2026-07-29
- CVE-2026-63030 / CVE-2026-60137 (WP2Shell) — WordPress Core pre-auth RCE chain moves to confirmed in-the-wild exploitation and CISA KEV2026-07-26
- Internet-facing enterprise and admin software crossed into confirmed exploitation again this week — ServiceNow, SharePoint, Check Point management, Langflow and WordPress core all moved to under-attack, and several leave persistence the patch does not remove2026-07-26
- An exposed WebDAV delivery lab shows industrialised .url/.lnk lure testing against CVE-2025-33053, with LLM-written tooling and ClickFix pages2026-07-26
- 2026-W29 looking ahead — items already in motion: WordPress WP2Shell and Firefox public exploit code, a SharePoint Pwn2Own chain half-patched until August, a withheld ShareFile CVE, and two EU regulatory clocks running2026-07-19
- WP2Shell: pre-auth RCE chain in stock WordPress core (CVE-2026-63030 + CVE-2026-60137) — out-of-band 7.0.2 patch, exploitation expected short-term2026-07-18
- SonicWall SMA 1000 zero-day exploitation (CVE-2026-15409/-15410): Volexity reconstructs UTA0533's full appliance-to-network kill chain2026-07-18
- July Patch Tuesday follow-through: a SharePoint pre-auth JWT bypass from a Pwn2Own chain (CVE-2026-55040) and a pre-auth Dynamics 365 RCE Microsoft expects to be exploited (CVE-2026-55944)2026-07-15
- Gogs CVE-2026-52806 moves from "no observed exploitation" to active cryptojacking campaign2026-06-29
- Oracle PeopleSoft CVE-2026-35273 attributed to ShinyHunters; confirmed zero-day, 100+ victims, education sector hit hardest2026-06-13
- PAN-OS GlobalProtect auth-bypass (CVE-2026-0257) — Unit 42 confirms attackers established working gateway sessions2026-06-10
- CVE-2026-47291 — Microsoft June Patch Tuesday: HTTP.sys pre-auth RCE (CVSS 9.8) headlines the largest-ever release (198 CVEs)2026-06-10
- CVE-2026-50751 — Check Point Security Gateway: IKEv1 VPN authentication bypass, actively exploited by a Qilin affiliate2026-06-09
- Check Point IKEv1 VPN Authentication Bypass (CVE-2026-50751)2026-06-09
- Looking ahead — 2026-W232026-06-01
- CVE-2026-0257: PAN-OS GlobalProtect Pre-Auth VPN Authentication Bypass2026-05-30
- CVE-2026-0257 — Palo Alto PAN-OS GlobalProtect: Pre-Auth Authentication Bypass via Certificate Reuse2026-05-30
- Rapid7 publishes unpatched Gogs argument-injection RCE with a Metasploit module; maintainer non-responsive2026-05-29
- Looking ahead — 2026-W222026-05-25
- CVE-2026-0257 — Palo Alto PAN-OS GlobalProtect pre-auth authentication bypass, exploited in two waves by the same actor2026-05-25
- Rapid7 Q1 2026 Threat Landscape Report: vulnerability exploitation now top initial-access vector at 38 %; KEV median time to listing collapses to 5 days2026-05-23
- Rapid7 Q1 2026 Threat Landscape Report — corroborates the structural shift; KEV-to-listing window collapsing2026-05-18
- UAT-8616 exploits Cisco Catalyst SD-WAN CVE-2026-20182; 10+ clusters exploit companion February 2026 CVEs; CISA Emergency Directive ED-26-03 issued2026-05-15
- CVE-2026-20182 — Cisco Catalyst SD-WAN Controller/Manager: pre-auth authentication bypass enabling full fabric takeover2026-05-15
- Cisco Catalyst SD-WAN: CVE-2026-20182 Authentication Bypass and UAT-8616 Kill Chain2026-05-15
- MuddyWater (Iran / MOIS) Chaos ransomware false-flag + Teams BEC2026-05-04
- cPanel / WHM — two emergency TSRs inside ten days: post-CVE-2026-41940 fleet now facing CVE-2026-29201/29202/292032026-05-04