CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Rapid7 security advisory (AV26-801)

unknownCVE-2026-18972
Serial Number: AV26-801 Date: August 11, 2026 As of August 11, 2026, Rapid7 is affected by a vulnerability in the following product: Velociraptor Prior to 0.77.2 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. CVE-2026-18972 Velociraptor authenticated identity-spoofing …

CSIRTS triage

What
Velociraptor prior to version 0.77.2 contains an authenticated identity-spoofing vulnerability.
Who is affected
Deployments of Velociraptor before version 0.77.2.
Urgency
Moderate urgency; the vulnerability requires authentication but allows identity spoofing, which could lead to privilege escalation or unauthorized access.
Action
Upgrade Velociraptor to version 0.77.2 or later.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Velociraptor

Get an email when a new Velociraptor advisory drops — max one per day, one-click unsubscribe.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
unknown
Published
2026-08-11
Exploitation
Not in CISA KEV at last sync

Original advisory: https://cyber.gc.ca/en/alerts-advisories/rapid7-security-advisory-av26-801

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-18972coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Canadian Centre for Cyber Security