The Rapid7 Blog:
Your Signal in the Security Noise

Insights, stories, and guidance from our global security and research teams.

Weekly security updates — no spam. Privacy Policy.

CVE-2023-27350: Ongoing Exploitation of PaperCut Remote Code Execution Vulnerability

Vulnerabilities and Exploits

CVE-2023-27350: Ongoing Exploitation of PaperCut Remote Code Execution Vulnerability

Drew Burton's avatar

Drew Burton

Raptor Technologies Volunteer Management Client-Side Security Controls (FIXED)

Vulnerabilities and Exploits

Raptor Technologies Volunteer Management Client-Side Security Controls (FIXED)

Rapid7's avatar

Rapid7

Backdoored 3CXDesktopApp Installer Used in Active Threat Campaign

Vulnerabilities and Exploits

Backdoored 3CXDesktopApp Installer Used in Active Threat Campaign

Rapid7's avatar

Rapid7

Multiple Vulnerabilities in Rocket Software UniRPC server (Fixed)

Vulnerabilities and Exploits

Multiple Vulnerabilities in Rocket Software UniRPC server (Fixed)

Ron Bowes's avatar

Ron Bowes

CVE-2023-0391: MGT-COMMERCE CloudPanel Shared Certificate Vulnerability and Weak Installation Procedures

Vulnerabilities and Exploits

CVE-2023-0391: MGT-COMMERCE CloudPanel Shared Certificate Vulnerability and Weak Installation Procedures

Tod Beardsley's avatar

Tod Beardsley

Microsoft Defender for Cloud Management Port Exposure Confusion

Vulnerabilities and Exploits

Microsoft Defender for Cloud Management Port Exposure Confusion

Tod Beardsley's avatar

Tod Beardsley

CVE-2022-21587: Rapid7 Observed Exploitation of Oracle E-Business Suite Vulnerability

Vulnerabilities and Exploits

CVE-2022-21587: Rapid7 Observed Exploitation of Oracle E-Business Suite Vulnerability

Glenn Thorpe's avatar

Glenn Thorpe

Multiple DMS XSS (CVE-2022-47412 through CVE-20222-47419)

Vulnerabilities and Exploits

Multiple DMS XSS (CVE-2022-47412 through CVE-20222-47419)

Tod Beardsley's avatar

Tod Beardsley

CVE-2023-22374: F5 BIG-IP Format String Vulnerability

Vulnerabilities and Exploits

CVE-2023-22374: F5 BIG-IP Format String Vulnerability

Ron Bowes's avatar

Ron Bowes

Exploitation of Control Web Panel CVE-2022-44877

Vulnerabilities and Exploits

Exploitation of Control Web Panel CVE-2022-44877

Caitlin Condon's avatar

Caitlin Condon

CVE-2022-47966: Rapid7 Observed Exploitation of Critical ManageEngine Vulnerability

Vulnerabilities and Exploits

CVE-2022-47966: Rapid7 Observed Exploitation of Critical ManageEngine Vulnerability

Glenn Thorpe's avatar

Glenn Thorpe

Refreshing Rapid7's Coordinated Vulnerability Disclosure Policy

Vulnerabilities and Exploits

Refreshing Rapid7's Coordinated Vulnerability Disclosure Policy

Tod Beardsley's avatar

Tod Beardsley

CVE-2022-41080, CVE-2022-41082: Rapid7 Observed Exploitation of `OWASSRF` in Exchange for RCE

Vulnerabilities and Exploits

CVE-2022-41080, CVE-2022-41082: Rapid7 Observed Exploitation of `OWASSRF` in Exchange for RCE

Glenn Thorpe's avatar

Glenn Thorpe

Cengage LTI Session Management Leakage

Vulnerabilities and Exploits

Cengage LTI Session Management Leakage

Tod Beardsley's avatar

Tod Beardsley

CVE-2022-42475: Critical Unauthenticated Remote Code Execution Vulnerability in FortiOS; Exploitation Reported

Vulnerabilities and Exploits

CVE-2022-42475: Critical Unauthenticated Remote Code Execution Vulnerability in FortiOS; Exploitation Reported

Glenn Thorpe's avatar

Glenn Thorpe

CVE-2022-4261: Rapid7 Nexpose Update Validation Issue (FIXED)

Vulnerabilities and Exploits

CVE-2022-4261: Rapid7 Nexpose Update Validation Issue (FIXED)

Tod Beardsley's avatar

Tod Beardsley

CVE-2022-41622 and CVE-2022-41800 (FIXED): F5 BIG-IP and iControl REST Vulnerabilities and Exposures

Vulnerabilities and Exploits

CVE-2022-41622 and CVE-2022-41800 (FIXED): F5 BIG-IP and iControl REST Vulnerabilities and Exposures

Ron Bowes's avatar

Ron Bowes

Rapid7’s Impact from OpenSSL Buffer Overflow Vulnerabilities (CVE-2022-3786 & CVE-2022-3602)

Vulnerabilities and Exploits

Rapid7’s Impact from OpenSSL Buffer Overflow Vulnerabilities (CVE-2022-3786 & CVE-2022-3602)

Rapid7's avatar

Rapid7

Rapid7’s Impact from Apache Commons Text Vulnerability (CVE-2022-42889)

Vulnerabilities and Exploits

Rapid7’s Impact from Apache Commons Text Vulnerability (CVE-2022-42889)

Rapid7's avatar

Rapid7

CVE-2021-39144: VMware Cloud Foundation Unauthenticated Remote Code Execution

Vulnerabilities and Exploits

CVE-2021-39144: VMware Cloud Foundation Unauthenticated Remote Code Execution

Caitlin Condon's avatar

Caitlin Condon

CVE-2022-40684: Remote Authentication Bypass Vulnerability in Fortinet Firewalls, Web Proxies

Vulnerabilities and Exploits

CVE-2022-40684: Remote Authentication Bypass Vulnerability in Fortinet Firewalls, Web Proxies

Glenn Thorpe's avatar

Glenn Thorpe