October 2026 Release Notes
Copy link

The Command Platform release notes include information about what’s new, which are updated monthly, and improvements and fixes, which are updated weekly.

ℹ️

Last updated: October 5, 2026

What’s New
Copy link

Learn about new features across the Command Platform. These features were released over the past month and are available now:

The Command Platform’s unified navigation and single platform application are now the default experience for eligible customers. All mainstream products — Vulnerability Management, SIEM, Cloud Security, Attack Surface Management, and Automation — load within a single application, reducing latency and friction when switching between products.

With this update, you can:

  • Move between products faster using the single platform application, which eliminates page reloads when switching contexts.
  • Use the redesigned collapsible vertical navigation, which takes up less screen space and displays only the products and capabilities you have access to.
  • Search for destinations across the platform, with support for legacy product names. For example, searching “IDR” returns SIEM-related results.
  • Access capabilities only available through Unified Navigation, including Consolidated User Settings, All Findings, All Vulnerabilities, and MDR Threat Hunts.

Impacted offering:

  • Command Platform

Top of page

SCIM Identity Provisioning
Copy link

The Command Platform now supports System for Cross-Domain Identity Management (SCIM), letting you automate account provisioning, updates, and deprovisioning directly from your identity provider (IdP). This eliminates manual account management and reduces the risk of unauthorized access from stale accounts.

With this update in Administration > Settings > SSO Settings, you can:

  • Automatically provision new employees with Command Platform access as soon as they’re added to your IdP.
  • Revoke access instantly when a user is removed from your IdP, closing the gap between offboarding and access removal.
  • Sync role and group changes automatically, keeping permissions aligned with each user’s current role without manual updates.

Impacted offering:

  • Command Platform

Risk
Copy link

Export bulk vulnerability data with any valid API key
Copy link

The Vulnerability Management Bulk Export API no longer requires an organization-level or platform administrator API key. Any valid API key can now authenticate bulk export requests, and returned data is automatically scoped to the permissions of the key used.

With this change, you can:

  • Use non-admin API keys to call the Bulk Export API without elevated credentials.
  • Follow least-privilege practices by scoping exports to only the data your key is authorized to access.
  • Reduce credential sprawl by eliminating the need to provision or share high-privilege admin keys for automated exports.

Impacted offering:

  • Vulnerability Management

Top of page

Empower cloud teams with expanded Remediation Hub access
Copy link

Remediation Hub is now available to all Cloud Security users, and administrator privileges are no longer required. Users inherit their existing Cloud Security access controls, so they only see remediations, assets, and vulnerabilities tied to the resources they’re authorized to view.

With this update in Response & Remediation > Remediation Hub, you can:

  • Give cloud resource owners direct visibility into prioritized remediation actions without admin involvement.
  • Reduce bottlenecks by enabling the teams responsible for cloud resources to act on remediations themselves.
  • Improve collaboration between security and cloud operations teams through shared, role-appropriate remediation data.
  • Maintain existing access controls while accelerating remediation across your organization.

Impacted offering:

  • Cloud Security

Top of page

Threat
Copy link

Curate your threat intelligence feed with Intelligence Watchlist
Copy link

In Rapid7 Threat Intelligence, you can now personalize your threat intelligence feed using the new Intelligence Watchlist. By selecting the locations, industries, and threat actors most relevant to your organization, you can focus your intelligence on the threats that matter to your specific security environment.

When a campaign matches your watchlist selections, it receives an Impact score in your Campaigns list, helping you instantly identify and prioritize the threats most relevant to your organization.

With this update in Intelligence > Intelligence Watchlist, you can:

  • Select specific locations, industries, and threat actors to build a curated threat intelligence feed tailored to your organization.
  • Surface relevant campaigns with an Impact score directly in your Campaigns list for faster threat prioritization.
  • Add threat actors to your watchlist directly from the Threat Actors page.

Impacted offering:

  • Threat Intelligence

Top of page

Query malware faster with the new Malware Library
Copy link

Threat Intelligence now includes Malware Profiles as a dedicated content type alongside Campaigns and Threat Actors. The new Malware Library gives you a single place to research malware families curated by Rapid7 Labs, with full context on behaviors, aliases, targeting, and related actors, campaigns, and CVEs.

With this update in Intelligence > Malware Library, you can:

  • Search and filter 770+ Malware Profiles curated by Rapid7 Labs by type, platform, targeted country, and industry.
  • Review a family’s aliases, confirmed capabilities, targeted locations, and first and last seen dates in a single profile.
  • Follow associations from a malware profile to related Campaigns, Threat Actors, CVEs, and IOCs.
  • View associated malware directly on Campaign and Threat Actor pages, with full bidirectional navigation coming in a follow-on update.
  • Search logs for IOCs directly from a malware profile to pivot from intelligence context to your own environment in one click.

Impacted offering:

  • Threat Intelligence

Top of page

Improvements and Fixes
Copy link

Keep track of improvements and fixes to core technology.

Application Security (InsightAppSec) and AppSpider
Copy link

No updates released at this time.

Top of page

Attack Surface Management (Surface Command)
Copy link

Top of page

Cloud Security (InsightCloudSec)
Copy link

Version 26.10.6
Copy link

Software release date: October 6, 2026 | Release notes published: October 5, 2026

No Release: Version 26.10.13

  • There will be no Cloud Security (InsightCloudSec) release on October 13, 2026. The next release will be version 26.10.20 on October 20, 2026.

New Features

  • Released Kubernetes Scanner v5.5.0 with memory improvements. Internal components and their versions are available in the chart value file.
    • View data using the helm show values <chart name> | grep -E 'Name:|Version:' command.
    • Update using the helm upgrade --install command referenced in the Kubernetes Scanner documentation.

Improved

  • Improved License page load time for installations with many cloud accounts.

Fixed

  • Fixed an issue where the Resource Creator attribution job could run concurrent instances in large environments, causing excessive database load and slowing Event-Driven Harvesting. Execution checks now prevent overlapping runs.
  • Fixed an issue where the AWS IAM delegation SNS webhook did not validate subscription-confirmation URLs before fetching them. URLs are now required to be HTTPS AWS SNS endpoints that resolve to a publicly routable address, redirects are no longer followed, and invalid URLs are rejected with a 400 error without being fetched. No configuration change is required and legitimate AWS SNS notifications are unaffected.
  • Fixed an issue where AWS:ServiceEventRuleHarvester failed with CLOUD_UNKNOWN_PROVIDER_ERROR when encountering EventBridge event buses encrypted with customer-managed KMS keys (CMK). Unreadable buses are now skipped without failing the harvest for other event buses in the same account.
  • Fixed an issue where removing the last Azure role assignment or group membership from a user, group, or role was not reflected after harvesting, causing stale Insight findings to persist.
  • Removed unnecessary license-expiry data from the table in Settings > System Administration > License > License Information.

Top of page

SIEM (InsightIDR)
Copy link

No updates released at this time.

Top of page

Vulnerability Management (InsightVM)
Copy link

Version 8.62.0
Copy link

Software release date: October 5, 2026 | Release notes published: October 5, 2026

Improved:

  • NTLM Authentication — Scan Engine Hostname Now Included in Authentication Requests. The scan engine now correctly identifies itself by hostname when authenticating using NTLM over SMB and HTTP, ensuring scan activity is accurately attributed in security audit logs and Microsoft Defender for Identity (MDI) and eliminating “UNKNOWN” source entries that could cause confusion during security monitoring.
  • PostgreSQL Version 15.18 now available. Upgrade the console’s internal database to PostgreSQL 15.18, incorporating the stability and security improvements included in this version.
    • Note: If you have not previously performed a minor PostgreSQL upgrade, this update is applied automatically when you upgrade to 8.62.0 or restart the console. If you have run a manual minor upgrade in the past, a Global Administrator must apply it manually in Administration > Maintenance > Run Manual Maintenance > Update PostgreSQL. The console will briefly enter maintenance mode during the update — wait for it to complete before refreshing and signing back in.
  • Oracle JRE — Patched Version Now Correctly Identified on Windows. The full version string for Oracle JRE on Windows is now captured accurately, including the patch segment (for example, 25.0.4.1 rather than 25.0.4), eliminating false positive vulnerability findings for assets running patched JRE builds.
  • Oracle HTTP Server — Detection Support Added. Authenticated fingerprinting is now supported for Oracle HTTP Server on both Windows and Linux, enabling accurate software inventory and vulnerability assessment for this product.
  • New CIS Policy Content: CIS Microsoft SQL Server 2025 Benchmark v1.0.0. Built-in policy content for the CIS Microsoft SQL Server 2025 Benchmark v1.0.0 is now available, enabling compliance assessments against the latest CIS hardening guidance for SQL Server 2025.

Fixed:

  • Resolved Spurious Encryption Warnings for Reverse-Paired Scan Engines. Scan engines configured with Engine-to-Console pairing were generating repeated “Connection to scan engine not encrypted” warnings in the Security Console log, causing unnecessary concern despite the connection being secure — this has been corrected.
  • Vulnerability Exceptions on Dynamic Asset Groups Causing Scan Instability. An issue where vulnerability exceptions scoped to dynamic asset groups using risk or vulnerability score-based filters could create a self-reinforcing cycle — causing assets to repeatedly enter and exit the group during scans — has been corrected. CVSSv3 score criteria are now restricted when creating exceptions of this type, ensuring consistent, stable scan results.
  • Check Point GAiA — False Positive Vulnerability Findings for Modern Jumbo Hotfix Packages. Vulnerability scans against modern Check Point GAiA R81.20 environments were generating false positive findings because the fingerprinter did not recognise current Jumbo Hotfix package naming formats, causing the highest installed version to be incorrectly calculated — detection has been updated to accurately identify all current package formats.

Top of page

Nexpose
Copy link

Nexpose Version 8.62.0
Copy link

Software release date: October 5, 2026 | Release notes published: October 5, 2026

Improved:

  • NTLM Authentication — Scan Engine Hostname Now Included in Authentication Requests. The scan engine now correctly identifies itself by hostname when authenticating using NTLM over SMB and HTTP, ensuring scan activity is accurately attributed in security audit logs and Microsoft Defender for Identity (MDI) and eliminating “UNKNOWN” source entries that could cause confusion during security monitoring.
  • PostgreSQL Version 15.18 now available. Upgrade the console’s internal database to PostgreSQL 15.18, incorporating the stability and security improvements included in this version.
    • Note: If you have not previously performed a minor PostgreSQL upgrade, this update is applied automatically when you upgrade to 8.62.0 or restart the console. If you have run a manual minor upgrade in the past, a Global Administrator must apply it manually in Administration > Maintenance > Run Manual Maintenance > Update PostgreSQL. The console will briefly enter maintenance mode during the update — wait for it to complete before refreshing and signing back in.
  • Oracle JRE — Patched Version Now Correctly Identified on Windows. The full version string for Oracle JRE on Windows is now captured accurately, including the patch segment (for example, 25.0.4.1 rather than 25.0.4), eliminating false positive vulnerability findings for assets running patched JRE builds.
  • Oracle HTTP Server — Detection Support Added. Authenticated fingerprinting is now supported for Oracle HTTP Server on both Windows and Linux, enabling accurate software inventory and vulnerability assessment for this product.
  • New CIS Policy Content: CIS Microsoft SQL Server 2025 Benchmark v1.0.0. Built-in policy content for the CIS Microsoft SQL Server 2025 Benchmark v1.0.0 is now available, enabling compliance assessments against the latest CIS hardening guidance for SQL Server 2025.

Fixed:

  • Resolved Spurious Encryption Warnings for Reverse-Paired Scan Engines. Scan engines configured with Engine-to-Console pairing were generating repeated Connection to scan engine not encrypted warnings in the Security Console log, causing unnecessary concern despite the connection being secure — this has been corrected.
  • Vulnerability Exceptions on Dynamic Asset Groups Causing Scan Instability. An issue where vulnerability exceptions scoped to dynamic asset groups using risk or vulnerability score-based filters could create a self-reinforcing cycle — causing assets to repeatedly enter and exit the group during scans — has been corrected. CVSSv3 score criteria are now restricted when creating exceptions of this type, ensuring consistent, stable scan results.
  • Check Point GAiA — False Positive Vulnerability Findings for Modern Jumbo Hotfix Packages. Vulnerability scans against modern Check Point GAiA R81.20 environments were generating false positive findings because the fingerprinter did not recognise current Jumbo Hotfix package naming formats, causing the highest installed version to be incorrectly calculated — detection has been updated to accurately identify all current package formats.

Top of page

Cyber GRC
Copy link

No updates released at this time.

Top of page

Digital Risk Protection (Threat Command)
Copy link

No updates released at this time.

Top of page

Rapid7 Agent (Insight Agent)
Copy link

No updates released at this time.

Top of page

Next-Generation Antivirus
Copy link

No updates released at this time.

Top of page

Ransomware Prevention
Copy link

No updates released at this time.

Top of page

Velociraptor
Copy link

No updates released at this time.

Top of page

Automation (InsightConnect)
Copy link

No updates released at this time.

Top of page

Rapid7 Network Sensor (Network Traffic Analysis)
Copy link

No updates released at this time.

Top of page