The Rapid7 Blog:
Your Signal in the Security Noise

Insights, stories, and guidance from our global security and research teams.

Weekly security updates — no spam. Privacy Policy.

CVE-2022-31660 and CVE-2022-31661 (FIXED): VMware Workspace ONE Access, Identity Manager, and vRealize Automation LPE

Threat Research

CVE-2022-31660 and CVE-2022-31661 (FIXED): VMware Workspace ONE Access, Identity Manager, and vRealize Automation LPE

Spencer McIntyre's avatar

Spencer McIntyre

QNAP Poisoned XML Command Injection (Silently Patched)

Exposure Management

QNAP Poisoned XML Command Injection (Silently Patched)

Jake Baines's avatar

Jake Baines

Primary Arms PII Disclosure via IDOR (FIXED)

Threat Research

Primary Arms PII Disclosure via IDOR (FIXED)

Tod Beardsley's avatar

Tod Beardsley

CVE-2022-35629..35632 Velociraptor Multiple Vulnerabilities (FIXED)

Products and Tools

CVE-2022-35629..35632 Velociraptor Multiple Vulnerabilities (FIXED)

Mike Cohen's avatar

Mike Cohen

CVE-2022-30526 (Fixed): Zyxel Firewall Local Privilege Escalation

Vulnerabilities and Exploits

CVE-2022-30526 (Fixed): Zyxel Firewall Local Privilege Escalation

Jake Baines's avatar

Jake Baines

CVE-2021-3779: Ruby-MySQL Gem Client File Read (FIXED)

Exposure Management

CVE-2021-3779: Ruby-MySQL Gem Client File Read (FIXED)

Tod Beardsley's avatar

Tod Beardsley

CVE-2022-31749: WatchGuard Authenticated Arbitrary File Read/Write (Fixed)

Exposure Management

CVE-2022-31749: WatchGuard Authenticated Arbitrary File Read/Write (Fixed)

Jake Baines's avatar

Jake Baines

CVE-2022-32230: Windows SMB Denial-of-Service Vulnerability (FIXED)

Threat Research

CVE-2022-32230: Windows SMB Denial-of-Service Vulnerability (FIXED)

Spencer McIntyre's avatar

Spencer McIntyre

CVE-2022-22977: VMware Guest Authentication Service LPE (FIXED)

Exposure Management

CVE-2022-22977: VMware Guest Authentication Service LPE (FIXED)

Jake Baines's avatar

Jake Baines

CVE-2022-30525 (FIXED): Zyxel Firewall Unauthenticated Remote Command Injection

Vulnerabilities and Exploits

CVE-2022-30525 (FIXED): Zyxel Firewall Unauthenticated Remote Command Injection

Jake Baines's avatar

Jake Baines

CVE-2022-28810: ManageEngine ADSelfService Plus Authenticated Command Execution (Fixed)

Exposure Management

CVE-2022-28810: ManageEngine ADSelfService Plus Authenticated Command Execution (Fixed)

Jake Baines's avatar

Jake Baines

CVE-2022-24527: Microsoft Connected Cache Local Privilege Escalation (Fixed)

Exposure Management

CVE-2022-24527: Microsoft Connected Cache Local Privilege Escalation (Fixed)

Jake Baines's avatar

Jake Baines

CVE-2022-1026: Kyocera Net View Address Book Exposure

Threat Research

CVE-2022-1026: Kyocera Net View Address Book Exposure

Tod Beardsley's avatar

Tod Beardsley

CVE-2021-4191: GitLab GraphQL API User Enumeration (FIXED)

Threat Research

CVE-2021-4191: GitLab GraphQL API User Enumeration (FIXED)

Jake Baines's avatar

Jake Baines

CVE-2021-20038..42: SonicWall SMA 100 Multiple Vulnerabilities (FIXED)

Exposure Management

CVE-2021-20038..42: SonicWall SMA 100 Multiple Vulnerabilities (FIXED)

Jake Baines's avatar

Jake Baines

CVE-2021-3546[78]: Akkadian Console Server Vulnerabilities (FIXED)

Vulnerabilities and Exploits

CVE-2021-3546[78]: Akkadian Console Server Vulnerabilities (FIXED)

Tod Beardsley's avatar

Tod Beardsley

CVE-2021-3927[67]: Fortress S03 WiFi Home Security System Vulnerabilities

Exposure Management

CVE-2021-3927[67]: Fortress S03 WiFi Home Security System Vulnerabilities

Tod Beardsley's avatar

Tod Beardsley

Fortinet FortiWeb OS Command Injection

Vulnerabilities and Exploits

Fortinet FortiWeb OS Command Injection

Tod Beardsley's avatar

Tod Beardsley

Metasploit Wrap-Up 8/6/21

Threat Research

Metasploit Wrap-Up 8/6/21

Matthew Kienow's avatar

Matthew Kienow

Multiple Open Source Web App Vulnerabilities Fixed

Products and Tools

Multiple Open Source Web App Vulnerabilities Fixed

Tod Beardsley's avatar

Tod Beardsley

CVE-2020-7387..7390: Multiple Sage X3 Vulnerabilities

Vulnerabilities and Exploits

CVE-2020-7387..7390: Multiple Sage X3 Vulnerabilities

Tod Beardsley's avatar

Tod Beardsley