The Rapid7 Blog:
Your Signal in the Security Noise

Insights, stories, and guidance from our global security and research teams.

Weekly security updates — no spam. Privacy Policy.

Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)

Vulnerabilities and Exploits

Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)

Jonah Burgess's avatar

Jonah Burgess

Metasploit Pro 5.1 Released

Products and Tools

Metasploit Pro 5.1 Released

The Metasploit Team's avatar

The Metasploit Team

Rapid7 Expands UK and Ireland Channel Presence Through Strategic Partnership with Exclusive Networks

Culture

Rapid7 Expands UK and Ireland Channel Presence Through Strategic Partnership with Exclusive Networks

Ross Baker's avatar

Ross Baker

Rapid7 at Black Hat USA 2026: See preemptive security in action

Detection and Response

Rapid7 at Black Hat USA 2026: See preemptive security in action

Emma Burdett's avatar

Emma Burdett

KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails

Vulnerabilities and Exploits

KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails

Rapid7 Labs's avatar

Rapid7 Labs

Rapid7 named a Leader in the IDC MarketScape: Worldwide MDR Service for Midmarket 2026 Vendor Assessment

Detection and Response

Rapid7 named a Leader in the IDC MarketScape: Worldwide MDR Service for Midmarket 2026 Vendor Assessment

Rapid7's avatar

Rapid7

Metasploit Framework 6.5 Released

Products and Tools

Metasploit Framework 6.5 Released

The Metasploit Team's avatar

The Metasploit Team

Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)

Vulnerabilities and Exploits

Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)

Rapid7's avatar

Rapid7

CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity

Vulnerabilities and Exploits

CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity

Rapid7's avatar

Rapid7

How AI is Rewriting the Zero-Day Playbook for Preemptive Security

Products and Tools

How AI is Rewriting the Zero-Day Playbook for Preemptive Security

Joel Alcon's avatar

Joel Alcon

Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)

Vulnerabilities and Exploits

Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)

Stephen Fewer's avatar

Stephen Fewer

The Next Evolution of MDR: Preemptive Defense and Agentic Investigation

Detection and Response

The Next Evolution of MDR: Preemptive Defense and Agentic Investigation

Mikayla Wyman's avatar

Mikayla Wyman

Rapid7 Cyber GRC is now available: Turn security action into compliance proof

Products and Tools

Rapid7 Cyber GRC is now available: Turn security action into compliance proof

Michael Chroney's avatar

Michael Chroney

Rapid7 and Exclusive Networks expand partnership to modernize security operations and accelerate customer success

Culture

Rapid7 and Exclusive Networks expand partnership to modernize security operations and accelerate customer success

Claudia Zoon's avatar

Claudia Zoon

What Happened Between OpenAI and Hugging Face?

Artificial Intelligence

What Happened Between OpenAI and Hugging Face?

Wade Woolwine's avatar

Wade Woolwine

CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild

Vulnerabilities and Exploits

CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild

Rapid7's avatar

Rapid7

What’s New in Rapid7 Products and Services: Q2 2026 in Review

Products and Tools

What’s New in Rapid7 Products and Services: Q2 2026 in Review

Ed Montgomery's avatar

Ed Montgomery

From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab

Threat Research

From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab

Anna Širokova's avatar
Jan Recinsky's avatar

Anna Širokova, Jan Recinsky

CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core

Vulnerabilities and Exploits

CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core

Rapid7 Labs's avatar

Rapid7 Labs

Metasploit Wrap Up: An HTTP to SMB relay plus Payload Improvements

Products and Tools

Metasploit Wrap Up: An HTTP to SMB relay plus Payload Improvements

Christopher Granleese's avatar

Christopher Granleese

CVE-2026-58644: Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild

Vulnerabilities and Exploits

CVE-2026-58644: Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild

Rapid7's avatar

Rapid7