Skip to content
Threat Feed

Vendor

Rapid7

6 briefs RSS
high advisory

Multiple Vulnerabilities in Rapid7 Velociraptor

Rapid7 Velociraptor is affected by multiple vulnerabilities allowing an authenticated remote attacker to perform arbitrary file manipulation, security bypass, remote code execution, and privilege escalation.

PoC Velociraptor
2t 1c updated
high advisory

Authenticated Identity Spoofing Vulnerability in Velociraptor

Rapid7 Velociraptor versions prior to 0.77.2 are affected by an authenticated identity-spoofing vulnerability, CVE-2026-18972, that may allow unauthorized access or impersonation within the platform.

Velociraptor vulnerability identity-management
1c
medium advisory

Multiple Vulnerabilities in Rapid7 Velociraptor

Multiple vulnerabilities in Rapid7 Velociraptor could allow an attacker to perform a denial-of-service attack or disclose sensitive information.

Velociraptor vulnerability denial-of-service information-disclosure
2r 2t
medium advisory

Multiple Vulnerabilities in Rapid7 Velociraptor

Multiple vulnerabilities in Rapid7 Velociraptor could allow an attacker to disclose information or cause a denial of service.

Velociraptor vulnerability denial-of-service information-disclosure
2r 3t
medium threat

Kerberos Traffic from Unusual Process

Detects network connections to the standard Kerberos port from an unusual process other than lsass.exe, potentially indicating Kerberoasting or Pass-the-Ticket activity on Windows systems.

Elastic Defend +22 kerberoasting credential-access lateral-movement windows
2r 2t
critical advisory

Rapid7 Velociraptor Improper Input Validation Vulnerability

Rapid7 Velociraptor versions prior to 0.76.2 contain an improper input validation vulnerability allowing authenticated remote attackers to achieve remote code execution on the server.

Velociraptor rce input-validation linux
2r 1t 1c