The Rapid7 Blog:
Your Signal in the Security Noise
Insights, stories, and guidance from our global security and research teams.
Featured posts
3928 Results
.jpeg?width=3840&quality=75)
Detection and Response
Rapid7 named a Leader in the IDC MarketScape: Worldwide MDR Service for Midmarket 2026 Vendor Assessment
Rapid7

Products and Tools
Metasploit Framework 6.5 Released
The Metasploit Team

Vulnerabilities and Exploits
Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)
Rapid7

Vulnerabilities and Exploits
CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity
Rapid7

Products and Tools
How AI is Rewriting the Zero-Day Playbook for Preemptive Security
Joel Alcon

Vulnerabilities and Exploits
Rapid7 Analysis: Check Point SmartConsole Authentication Bypass (CVE-2026-16232)
Stephen Fewer

Detection and Response
The Next Evolution of MDR: Preemptive Defense and Agentic Investigation
Mikayla Wyman

Products and Tools
Rapid7 Cyber GRC is now available: Turn security action into compliance proof
Michael Chroney
Culture
Rapid7 and Exclusive Networks expand partnership to modernize security operations and accelerate customer success
Claudia Zoon

Artificial Intelligence
What Happened Between OpenAI and Hugging Face?
Wade Woolwine

Vulnerabilities and Exploits
CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
Rapid7

Products and Tools
What’s New in Rapid7 Products and Services: Q2 2026 in Review
Ed Montgomery

Threat Research
From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab
Anna Širokova, Jan Recinsky

Vulnerabilities and Exploits
CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core
Rapid7 Labs

Products and Tools
Metasploit Wrap Up: An HTTP to SMB relay plus Payload Improvements
Christopher Granleese

Vulnerabilities and Exploits
CVE-2026-58644: Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild
Rapid7

Vulnerabilities and Exploits
Sunsetting the Public AttackerKB Platform
Douglas McKee, Director, Vulnerability Intelligence

Vulnerabilities and Exploits
Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)
Rapid7

Detection and Response
Investigating Persistence Mechanisms in AWS
Jan Blažek

Exposure Management
Patch Tuesday - July 2026
Adam Barnett

Vulnerabilities and Exploits
CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)
Stephen Fewer

