The Rapid7 Blog:
Your Signal in the Security Noise
Insights, stories, and guidance from our global security and research teams.
Featured posts
271 Results

Vulnerabilities and Exploits
CVE-2023-20198: Active Exploitation of Cisco IOS XE Zero-Day Vulnerability
Caitlin Condon
![Multiple Vulnerabilities in South River Technologies Titan MFT and Titan SFTP [FIXED]](/_next/image/?url=https%3A%2F%2Fimages.contentstack.io%2Fv3%2Fassets%2Fblte4f029e766e6b253%2Fblt1de2821d1eac3ffb%2F683ddc6570aa95f50bfe2f13%2Fvuln-disclosure-banner.jpeg&w=1920&q=75)
Vulnerabilities and Exploits
Multiple Vulnerabilities in South River Technologies Titan MFT and Titan SFTP [FIXED]
Ron Bowes

Vulnerabilities and Exploits
CVE-2023-22515: Zero-Day Privilege Escalation in Confluence Server and Data Center
Caitlin Condon

Vulnerabilities and Exploits
CVE-2023-4528: Java Deserialization Vulnerability in JSCAPE MFT (Fixed)
Ron Bowes

Vulnerabilities and Exploits
Active Exploitation of Multiple Adobe ColdFusion Vulnerabilities
Caitlin Condon

Vulnerabilities and Exploits
Widespread Exploitation of Zyxel Network Devices
Drew Burton

Vulnerabilities and Exploits
CVE-2023-27350: Ongoing Exploitation of PaperCut Remote Code Execution Vulnerability
Drew Burton

Vulnerabilities and Exploits
Raptor Technologies Volunteer Management Client-Side Security Controls (FIXED)
Rapid7

Vulnerabilities and Exploits
Backdoored 3CXDesktopApp Installer Used in Active Threat Campaign
Rapid7

Vulnerabilities and Exploits
Multiple Vulnerabilities in Rocket Software UniRPC server (Fixed)
Ron Bowes

Vulnerabilities and Exploits
CVE-2023-0391: MGT-COMMERCE CloudPanel Shared Certificate Vulnerability and Weak Installation Procedures
Tod Beardsley

Vulnerabilities and Exploits
Microsoft Defender for Cloud Management Port Exposure Confusion
Tod Beardsley

Vulnerabilities and Exploits
CVE-2022-21587: Rapid7 Observed Exploitation of Oracle E-Business Suite Vulnerability
Glenn Thorpe

Vulnerabilities and Exploits
Multiple DMS XSS (CVE-2022-47412 through CVE-20222-47419)
Tod Beardsley

Vulnerabilities and Exploits
CVE-2023-22374: F5 BIG-IP Format String Vulnerability
Ron Bowes

Vulnerabilities and Exploits
Exploitation of Control Web Panel CVE-2022-44877
Caitlin Condon

Vulnerabilities and Exploits
CVE-2022-47966: Rapid7 Observed Exploitation of Critical ManageEngine Vulnerability
Glenn Thorpe

Vulnerabilities and Exploits
Refreshing Rapid7's Coordinated Vulnerability Disclosure Policy
Tod Beardsley

Vulnerabilities and Exploits
CVE-2022-41080, CVE-2022-41082: Rapid7 Observed Exploitation of `OWASSRF` in Exchange for RCE
Glenn Thorpe

Vulnerabilities and Exploits
Cengage LTI Session Management Leakage
Tod Beardsley

Vulnerabilities and Exploits
CVE-2022-42475: Critical Unauthenticated Remote Code Execution Vulnerability in FortiOS; Exploitation Reported
Glenn Thorpe