Rapid7
Rapid7 Insightvm: vulnerabilities and CVEs
Rapid7 Insightvm has 11 published vulnerabilities, 3 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs11
Last 12 months3
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-89325 | High (7.8) | 0.13% | — | Sep 24, 2026 | An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbitrary code as SYSTEM via a planted executable resolved from the… |
| CVE-2026-14172 | High (7.8) | 0.16% | — | Jul 24, 2026 | Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential… |
| CVE-2026-1568 | Critical (9.6) | 0.15% | — | Feb 3, 2026 | Rapid7 InsightVM versions before 8.34.0 contain a signature verification issue on the Assertion Consumer Service (ACS) cloud endpoint that could allow an attacker to gain unauthorized access to InsightVM accounts setup… |
| CVE-2024-6504 | Medium (5.3) | 0.32% | — | Jul 18, 2024 | Rapid7 InsightVM Console versions below 6.6.260 suffer from a protection mechanism failure whereby an attacker with network access to the InsightVM Console can cause it to overload or crash by sending repeated invalid… |
| CVE-2024-2745 | Low (3.3) | 0.18% | — | Apr 2, 2024 | Rapid7's InsightVM maintenance mode login page suffers from a sensitive information exposure vulnerability whereby, sensitive information is exposed through query strings in the URL when login is attempted before the… |
| CVE-2021-3844 | Medium (5.4) | 0.36% | — | Mar 24, 2023 | Rapid7 InsightVM suffers from insufficient session expiration when an administrator performs a security relevant edit on an existing, logged on user. For example, if a user's password is changed by an administrator due… |
| CVE-2023-0681 | Medium (6.1) | 0.33% | — | Mar 20, 2023 | Rapid7 InsightVM versions 6.6.178 and lower suffers from an open redirect vulnerability, whereby an attacker has the ability to redirect the user to a site of the attacker’s choice using the ‘page’ parameter of the… |
| CVE-2017-5242 | High (7.7) | 0.38% | — | Jan 12, 2023 | Nexpose and InsightVM virtual appliances downloaded between April 5th, 2017 and May 3rd, 2017 contain identical SSH host keys. Normally, a unique SSH host key should be generated the first time a virtual appliance boots. |
| CVE-2022-4261 | Medium (6.5) | 0.31% | — | Dec 8, 2022 | Rapid7 Nexpose and InsightVM versions prior to 6.6.172 failed to reliably validate the authenticity of update contents. This failure could allow an attacker to provide a malicious update and alter the functionality of… |
| CVE-2019-5641 | Medium (5.3) | 0.38% | — | Sep 21, 2022 | Rapid7 InsightVM suffers from an information exposure issue whereby, when the user's session has ended due to inactivity, an attacker can use the Inspect Element browser feature to remove the login panel and view the… |
| CVE-2019-5615 | Medium (6.5) | 0.79% | — | Apr 9, 2019 | Users with Site-level permissions can access files containing the username-encrypted passwords of Security Console Global Administrators and clear-text passwords for restoring backups, as well as the salt for those… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.