{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3arapid7velociraptor/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:rapid7:velociraptor:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":5.5,"id":"CVE-2025-6264"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-MAUZY0X00-VELOCIRAPTOR_CVE-2025-6264_POC\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["Velociraptor"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Rapid7"],"content_html":"\u003cp\u003eRapid7 Velociraptor, an endpoint visibility and incident response tool, is affected by multiple vulnerabilities that enable an authenticated remote attacker to compromise system integrity and security posture. The vulnerabilities, as reported by the BSI, allow for arbitrary file manipulation, bypass of established security controls, remote code execution (RCE), and privilege escalation.\u003c/p\u003e\n\u003cp\u003eVelociraptor is a powerful agent-based tool often deployed with high-level system privileges to facilitate forensic data collection and live response. Successful exploitation of these vulnerabilities is particularly critical because they allow a malicious actor with initial authentication to gain control over the endpoint agent, potentially leading to full administrative compromise of the underlying host. Defenders must prioritize patching or isolating affected instances until updates are applied, as this tool is a common target for attackers looking to subvert security monitoring capabilities or deploy persistent backdoors.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for complete system takeover, including the ability to execute arbitrary code with elevated privileges, manipulate forensic evidence, and bypass security monitoring controls. Given the tool's intended role in incident response and security auditing, its compromise provides attackers with stealthy persistence and deep visibility into the host environment, potentially impacting any enterprise network where Velociraptor is utilized for endpoint security management.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReview current deployment of Velociraptor and ensure all agents and the management server are updated to the latest vendor-provided release.\u003c/li\u003e\n\u003cli\u003eAudit logs for authenticated sessions from unexpected or suspicious source IP addresses to identify potential unauthorized use of the management interface.\u003c/li\u003e\n\u003cli\u003eRestrict administrative access to the Velociraptor management console to a minimal set of highly trusted users and utilize multi-factor authentication (MFA) where possible.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized file modifications or unexpected process executions originating from the Velociraptor binary or service accounts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T13:27:53Z","date_published":"2026-08-24T15:55:50Z","id":"https://feed.craftedsignal.io/briefs/2026-08-velociraptor-vulnerabilities/","summary":"Rapid7 Velociraptor is affected by multiple vulnerabilities allowing an authenticated remote attacker to perform arbitrary file manipulation, security bypass, remote code execution, and privilege escalation.","title":"Multiple Vulnerabilities in Rapid7 Velociraptor","url":"https://feed.craftedsignal.io/briefs/2026-08-velociraptor-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:rapid7:velociraptor:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}