September 2026 Release Notes
The Command Platform release notes include information about what’s new, which are updated monthly, and improvements and fixes, which are updated weekly.
Last updated: September 28, 2026
What’s New
Learn about new features across the Command Platform. These features were released over the past month and are available now:
Attack surface
Your attack surface is comprised of all of the potential entry points that attackers could exploit across your systems, applications, and networks. Developing knowledge of your attack surface is a key goal in improving your company’s security posture.
- Communicate remediation priorities faster with AI-summarized reports (Surface Command, Exposure Command)
- Unify more remediation activity with CrowdStrike data in Remediation Hub (Surface Command, Exposure Command)
- Endpoint process start events now include user identity context
Communicate remediation priorities faster with AI-summarized reports
Remediation Hub now includes a Top Remediations Report with AI Summary, making it easier to share clear, actionable remediation context with asset owners and other stakeholders. The AI-generated summary that appears in Remediation Hub is now available directly in the report, giving stakeholders consistent insight into what needs to be fixed, why it matters, and what to do next without requiring manual explanation.
With this update in Risk > Remediation Hub, you can:
Share context alongside each remediation, including potential impact and recommended next steps. Provide stakeholders with a consistent experience between what teams view in the product and what they receive in reports. Reduce manual follow-up by delivering clear, self-explanatory remediation context directly in the report. Export reports in HTML or CSV format to meet different stakeholder needs.
Impacted offerings:
- Surface Command
- Exposure Command
Unify more remediation activity with CrowdStrike data in Remediation Hub
Remediation Hub now surfaces remediation recommendations from CrowdStrike, giving you a more unified view of remediation activity across your environment. Customers using the latest CrowdStrike connector for Rapid7 Attack Surface Management will see CrowdStrike findings directly alongside remediation data from other sources, reducing the need to switch between tools to prioritize and act on findings.
With this update in Risk > Remediation Hub, you can:
- View CrowdStrike remediation recommendations directly within Remediation Hub.
- Prioritize CrowdStrike findings alongside data from other remediation sources in a single workflow.
- Reduce context switching with a more unified remediation experience across environments.
Impacted offerings:
- Surface Command
- Exposure Command
Endpoint process start events now include user identity context
Process start events now automatically include the associated LDAP or Active Directory (AD) user, connecting endpoint activity with identity context across detection and investigation workflows. Previously, users needed to manually correlate endpoint activity with identity data to determine which user executed a process. Process start events now include a top-level user field and associated user RRN, allowing alerts and investigations to surface the attributed user automatically.
This enhancement in Alerts and Investigations helps you:
- View attributed user details directly in alerts and investigations.
- Correlate process activity with the user’s endpoint, cloud, and identity activity.
- See relevant user activity in investigation timelines and user pages.
- Investigate endpoint activity associated with users who have elevated directory privileges.
This additional identity context reduces manual correlation during triage and helps analysts more quickly understand who is associated with endpoint activity.
Impacted Offerings:
- SIEM
Threat
A threat is any potential event or action that could exploit vulnerabilities in a system, causing harm to assets, data, or operations. Threats can originate from various sources, including malicious actors, natural disasters, or unintentional human errors.
- Access continuous threat hunting visibility with MDR Threat Hunting
- Monitor data collection health with the Environment Health Dashboard
Access continuous threat hunting visibility with MDR Threat Hunting
MDR customers can now view every completed threat hunt Rapid7 performs on their behalf directly in the Command Platform. The new Threat Hunts page brings proactive hunting activity out of monthly reports and into a continuously updated, self-service experience, giving you and your Cybersecurity Advisor a shared, always-current record of hunting work.
With this capability in Response & Remediation > Threat Hunts, you can:
- Browse a searchable list of all completed hunts, with summary metric cards for quick status checks.
- Explore full hunt detail pages, including the Threat Brief, description, recommended actions, indicators of compromise (IOCs), and the queries used.
- Replay hunt queries directly in Log Search with the original time range pre-populated.
- Generate PDF or HTML reports on demand or on a schedule at both the individual hunt level and across a configurable time period.
Impacted offerings:
- MDR
Monitor data collection health with the Environment Health Dashboard
You can now monitor the health of your data collection environment from a single, dedicated page. The Environment Health Dashboard consolidates health metrics across your agents, collectors, event sources, network sensors, orchestrators, honeypots, scan engines, and data exporters, giving you a clear, current picture of your data pipeline without having to navigate across multiple pages.
With this capability in Data Connectors > Environment Health, you can:
- View key counts for each data source type by state, including online, offline, and stale, in the KPI bar and state bar chart.
- Identify known issues across your data sources in the issue feed, sorted by severity, with direct links to relevant documentation.
- Review collector resource utilization, including memory, CPU, and storage, in the resourcing table to catch capacity issues before they affect collection.
- Quickly identify event sources that are stopped or have been inactive for more than 24 hours.
- Export dashboard data as a PDF or HTML report.
Impacted offerings:
- SIEM (MDR)
- Incident Command
Cyber GRC
- Automate evidence collection across the employee lifecycle with the Workday integration
- Create tasks faster with a guided, step-by-step workflow
- Validate SSO configurations automatically with Authentication Provider URI checks
Automate evidence collection across the employee lifecycle with the Workday integration
The Workday integration in Rapid7 Cyber GRC now covers the full employee lifecycle, from onboarding through offboarding, so access review controls can pull automated evidence without manual collection.
With this update, you can:
- Automatically generate access review evidence tied to employment status changes in Workday.
- Reduce the manual effort required to prepare for user access reviews.
- Keep access review controls current as employees join, change roles, or leave the organization.
Create tasks faster with a guided, step-by-step workflow
Task creation in Rapid7 Cyber GRC now uses a guided, step-by-step flow instead of a single long form, making it faster and less error-prone to create new tasks.
Validate SSO configurations automatically with Authentication Provider URI checks
OIDC and SAML configurations in Rapid7 Cyber GRC now validate the Authentication Provider URI automatically, helping teams catch SSO misconfigurations before they cause login issues.
Improvements and Fixes
Keep track of improvements and fixes to core technology.
Application Security (InsightAppSec) and AppSpider
Version 7.5.029
Software release date: September 9, 2026 | Release notes published: September 9, 2026
New Features:
- AI Vulnerability Validator: Expanded Module Support - Integrated AWS Bedrock LLM verification for LDAP Injection findings, expanding the AI Vulnerability Validator suite alongside existing Blind SQL, Blind NoSQL, SQL Injection, and Remote File Inclusion (RFI) validation models to automatically evaluate and filter false positives.
- AI Validator FP Transparency Logging - Enabled automated generation of assessment log/report artifacts when the AI Vulnerability Validator is enabled, documenting every finding flagged as a false positive and excluded from scan results.
- ALF v2.1.1 Infrastructure Upgrade - Upgraded the Application Layer Framework (ALF) to v2.1.1, introducing native One-Time Password (OTP) support without manual hook setups, expanded ALF logging visibility, and optimized default configuration parameters.
- Technology Detection Evidence Context - Technology Detection vulnerability findings now incorporate detailed “Detection Method” and “Match Details” telemetry forwarded directly from R7Crawler.
Improved:
- AppSec Scan Engine
- Dynamic Memory Management - Optimized memory caching mechanisms during scanning to resolve memory allocation issues and prevent scan failures caused by insufficient memory.
- ASP.NET Core Configuration Leak Detection - Upgraded the Predictable Resource Location module to identify exposed ASP.NET Core / .NET Core configuration files located in web roots that leak sensitive credentials and environment secrets.
- Session Strength False Positives - Corrected module testing logic to ignore non-authorization tokens, eliminating false positive session strength findings.
- FrontPage/SharePoint Clean-up - Remediated false positive triggers affecting non-vulnerable Microsoft SharePoint environments.
- Per-URL Failure Tracking - Enhanced consecutive error handling by introducing per-URL failure tracking and configurable controls to block repeatedly failing URLs from stalling engine runs.
- Runtime Security Upgrades - Updated the installed .NET 8 runtime component from 8.0.29 to 8.0.30.
- Attack Data Defs - Updated analyze profiles to detect recent Drupal iterations and resolved edge cases during meta tag evaluations.
- R7 Crawler
- Browser & Driver Upgrades - Upgraded R7Crawler to Chromium version 151.0.7922.34 and bumped Selenium ChromeDriver to version 152.0.7977.64.
- Partial Page Load Support - Requests that time out waiting for total page load but achieve
DOMContentLoadedare logged and processed as valid partial-load states. - Link Ingestion & Coverage - Optimized processing of discovered
hreftargets to increase overall crawl depth during Chromium-driven scans. - Bot Detection Evasion - Refined
navigator.webdrivermasking controls to improve bot avoidance on protected targets. - Session Check Logic - Automatically suppresses
isLoggedIndetection routines on pages that fail to load.
Fixed:
- AppSec Scan Engine
- Technology Detection Validation Scans - Fixed inconsistent behavior during validation scans by adding full validation scan support to the Technology Detection module.
Attack Surface Management (Surface Command)
Version 1.0.942
Software release date: September 24, 2026 | Release notes published: September 25, 2026
Improved:
- Connector profile rows now have separate Edit and Delete menus, so edit actions no longer look disabled.
- Expanding a connector profile now opens the Credentials tab first, so you can edit credentials without switching tabs.
- The Saved Queries table now shows separate, sortable Dashboards and Widgets columns for the dashboards and widgets that use each query. Tooltips list their names.
- The light gray widget background is now darker and easier to tell apart from white widgets on more monitors.
Fixed:
- Asset information cards no longer fail to load with a server error for assets that have installed software.
- Copying a widget query from View query results now keeps its
includedirectives, so the copy picks up later changes to the included query. - Exporting large dashboard drill-down results to CSV no longer crashes the browser tab.
- Queries that include a saved query ending in
RETURN DISTINCTno longer return duplicate results.
Connectors
The following connectors were updated in the Extension Library since the previous release. Connector updates are published independently and may have been available before this release date.
Updated Connectors
- Armis: Fixed an import failure when Armis returns
Manyfor the paginationtotal. - Crowdstrike Falcon:
- Software, Unmanaged Devices, and Vulnerabilities: a missing permission now logs a warning, and the import continues.
- Host Groups: a missing
Host Groups: Readpermission now fails the Devices import.
- Halcyon:
- Authentication failures now show the granular Halcyon login error message instead of a generic HTTP status.
- Removed surrounding whitespace from the username and password settings before authenticating.
- Nozomi Vantage: Fixed a schema validation problem where
NozomiDevice.vlan_idcontained integers instead of strings. - UpGuard: Added an optional API URL setting for regional UpGuard tenants, and 403 error messages are now logged.
Version 1.0.941
Software release date: September 16, 2026 | Release notes published: September 16, 2026
Improved:
- The Connector detail panel now hides the Workflows and Functions tabs for users without the required permissions.
Connectors
The following connectors were updated in the Extension Library since the previous release. Connector updates are published independently and may have been available before this release date.
New Connectors
- DNS Made Easy: DNS Made Easy provides high-performance managed DNS services to ensure increased uptime, reduce IT workload, and boost performance. This connector imports details of managed domains into the Rapid7 Platform.
Updated Connectors
- BitSight:
- Added include and exclude organizations connector settings.
- Renamed the Patching Cadence risk vector title to Critical Vulnerability Management.
get_company_relationships: Clear error when no my-company GUID is returned; import continues.
- Cisco Meraki: Coerce
CiscoMerakiClient.adaptivePolicyGroupto string to prevent schema validation failures when the Meraki API returns it as an integer. - Infoblox NIOS DDI:
- Fail fast on an unresponsive superhost endpoint instead of stalling the ingest.
- Fix superhost pagination so more than the first page is collected.
- Added CNA license pre-flight check to skip superhost ingest on DDI-only grids.
- Added fault-tolerant superhost collection that continues ingest on 500 errors.
- ManageEngine Endpoint Central:
- Handle Patch Manager Plus without Endpoint Central.
- Clarify documentation for Patch Manager Plus-only environments.
Version 1.0.938
Software release date: September 1, 2026 | Release notes published: September 8, 2026
Fixed:
- The Test Connection button is now available only for connectors supporting this feature.
- The Widget filter editor now retains lone Timeframe filters for trend widgets upon saving.
Connectors
The following connectors were updated in the Extension Library since the previous release. Connector updates are published independently and may have been available before this release date.
Updated Connectors
- Anthropic: Added import of organizations, organization users, roles, and groups from the Anthropic Compliance API.
- BlackBerry Cylance: Updated broken documentation link in requirements. BlackBerry Cylance is now part of Arctic Wolf Aurora EDR.
- Check Point Harmony Endpoint:
- 401 authentication errors no longer occur; connector now re-authenticates when the session token expires.
- 400 errors when running the test function no longer occur.
- Cisco Duo: Added proper reference to CiscoDuoPhone.
- Crowdstrike Falcon:
- New
Host Groupssetting: Only import Devices (and their Alerts, Vulnerabilities, and Software) that belong to the given Host Groups (comma-separated). Requires theHost Groups: Readpermission. - CrowdstrikeSoftwareInstallation: Import failures caused by Windows installation paths ending in a backslash no longer occur.
- New
- Devo SIEM: Scope data control configuration items per connection profile to prevent cross-profile key collisions
- FortiClient EMS: Shorten file path for refdocs to fix packaging error.
- Google Drive: Scoped data control configuration items per connection profile to prevent cross-profile key collisions.
- Google Workspace: Scoped data control configuration items per connection profile to prevent cross-profile key collisions.
- Infoblox NIOS DDI: Fixed 500 error on superhost endpoint by removing unsupported fields and deferring paging to subsequent requests.
- Ivanti Neurons for ITSM: Shortened workflow file path to fix packaging error.
- ManageEngine Endpoint Central: Remove sample data files with paths exceeding packaging limit.
- ManageEngine OpManager: Shortened file path for functions module to fix packaging error.
- Microsoft 365: Shortened file paths to fix packaging error.
- Microsoft AD Certificate Services: Fixed large-CA imports.
- Microsoft Defender EASM: Shortened file path for functions module to fix packaging error.
- Microsoft Defender for IoT: Shortened file path for functions module to fix packaging error.
- Microsoft Intune:
- Added MicrosoftIntuneGroup type.
- New
Group Type(s)setting added. NeedsGroup.Read.AllandGroupMember.Read.Allpermission. - Software installations are now collected by default via a single whole-tenant report export, replacing the per-app device fan-out that could not complete on large tenants. On a tenant with 39,180 applications and 1,665,687 installations, the software import feed now completes in under 40 minutes, where it previously ran for days without finishing.
- Bound the number of in-flight export jobs so the per-device export strategy drains instead of growing on every pass.
- Stream the software export through disk so memory use stays flat regardless of tenant size.
- Write export scratch files to a fixed cache directory instead of a temporary one.
- Fix software import feed failures caused by Microsoft Graph throttling by adding a fixed backoff and retry strategy for managed-device requests.
- Improve software export performance with bulk processing and streaming.
- Add access token caching to reduce redundant authentication calls.
- Microsoft SQL: Scoped data control configuration items per connection profile to prevent cross-profile key collisions.
- Mimecast: Fixed packaging issue.
- Okta: Added OktaRole type and the standard administrator roles.
- Palo Alto Cortex Xpanse: Shortened file path for functions module to fix packaging error.
- PostgreSQL: Scoped data control configuration items per connection profile to prevent cross-profile key collisions.
- SSH File Transfer Protocol (SFTP): Scoped data control configuration items per connection profile to prevent cross-profile key collisions.
- Shodan: Scoped data control configuration items per connection profile to prevent cross-profile key collisions.
- Slack:
- Replaced the slack-bolt dependency with slack_sdk.
- Workflow posting message changes.
- Snowflake: Schema validation improvements.
- Splunk: Scope data control configuration items per connection profile to prevent cross-profile key collisions.
- TOPdesk:
- Added new
TOPdeskIncidenttype and incident data import. - Added
Import Incidents?setting to enable/disable incident import (default: disabled). - Added
Import Only Active Incidents?setting to limit imports to non-closed incidents (default: enabled). - Requires read permission on the
Call Management→First-line callsandSecond-line callsmodules on the TOPdesk API Token when incident import is enabled.
- Added new
Cloud Security (InsightCloudSec)
Release availability for self-hosted users
Self-hosted users are able to download the latest version usually six business days after SaaS users are upgraded from the following locations:
- Terraform deployments: Public S3 bucket . Modules can be updated with the
terraform get -updatecommand. - Amazon Elastic Container Repository (ECR) deployments - You can obtain the ECR build images for this version from the InsightCloudSec ECR Gallery
Version 26.9.29
Software release date: September 29, 2026 | Release notes published: September 28, 2026
Improved
- Resource state and last harvest time in Layered Context: Layered Context now shows each resource’s lifecycle state as reported by the cloud provider, along with last harvest time.
- OCI Harvesting Improvements: Cloud user harvesting for Oracle Cloud Infrastructure now makes fewer API calls, reducing the risk of hitting OCI Identity Domains rate limits on large tenancies.
- Container vulnerability export: Container vulnerability findings can now be exported from the Layered Context list view as a CSV file, with one row per container, CVE, and affected package.
New Compliance Packs
- Added the CIS AWS Database Services Benchmark v1.0.0 compliance pack which covers 22 controls across Aurora, RDS, DynamoDB, ElastiCache, Redshift, DocumentDB, Neptune, and Timestream.
- Added the CIS Microsoft Azure Database Services Benchmark v2.0.0 compliance pack which covers 47 controls across Azure Cache for Redis, Azure Cosmos DB, Azure Data Factory, Azure Database for MySQL, Azure Database for PostgreSQL, and Azure SQL Database. Available for Azure, Azure Gov, and Azure China.
New Insights
- Database Instance Not Enforcing Transit Encryption (AWS): Identifies Amazon RDS Database Instances that do not enforce SSL/TLS encryption in transit, excluding DocumentDB and Neptune instances.
- Database Instance Without Automatic Backups (AWS): Identifies Amazon RDS Database Instances that do not have automated backups enabled (backup retention period of 0), excluding DocumentDB and Neptune instances.
Updated Query Filters
- Storage Container Public Access Via Legacy Access Control List: Updated to exclude storage containers with uniform bucket-level access enabled, as this setting disables ACLs and prevents public exposure through legacy ACL controls.
Fixed
- Fixed stale GCP service account role bindings persisting after revocation, which caused false positives in role-based Insights.
Version 26.9.22
Software release date: September 22, 2026 | Release notes published: September 21, 2026
Improved
- CrowdStrike Falcon agent Query Filters now support Oracle Cloud Infrastructure (OCI) compute instances, alongside AWS, Azure, and GCP. Security teams can now identify OCI compute instances based on CrowdStrike Falcon agent presence.
Harvester Updates
- Azure Database Instance (Flexible Server): Added support for harvesting private endpoint connection counts for Azure Database for MySQL and PostgreSQL Flexible Servers.
- Azure Distributed Table (Cosmos DB): Added support for harvesting the
disableLocalAuthproperty and detecting whether the Cosmos DB account’s firewall allows Azure datacenter traffic (0.0.0.0in IP rules).
New Insights
- Distributed Table With Local Authentication Enabled: Identifies Azure Cosmos DB accounts that have local (key-based) authentication enabled instead of using Microsoft Entra ID only.
- Distributed Table Encrypted With Provider Managed Key: Identifies Azure Cosmos DB accounts that use provider-managed (service-managed) keys for encryption instead of customer-managed keys (CMK).
- Distributed Table Without Network Traffic Restrictions: Identifies Azure Cosmos DB accounts that allow all network traffic or have the firewall configured to accept connections from all Azure datacenters.
- Database Instance Without Microsoft Entra-Only Authentication (MySQL): Identifies Azure Database for MySQL Flexible Servers that do not have Microsoft Entra authentication configured as the only authentication method.
- Database Instance Without Private Endpoint (MySQL Flexible Server): Identifies Azure Database for MySQL Flexible Servers that do not have private endpoints configured.
- PostgreSQL Database Instance With Public Network Access Enabled: Identifies PostgreSQL Database Instances that have Public Network Access Enabled.
- PostgreSQL Database Instance Without Private Endpoint Connection: Identifies Azure Database for PostgreSQL Flexible Servers that do not have a private endpoint connection configured.
- Database Instance Firewall Allows Public Ingress (SQL Server): Identifies SQL Server Database Instances with a firewall rule that allows public ingress. On Azure, a rule allows public ingress when its start IP is
0.0.0.0and its end IP is any address other than0.0.0.0(for example0.0.0.0to255.255.255.255). A rule spanning exactly0.0.0.0to0.0.0.0grants access only to Azure services and is not flagged.
New Query Filters
- Distributed Table Local Authentication Configuration: Identifies Distributed Tables (Cosmos DB accounts) based on whether local authentication is enabled or disabled. By default, this Query Filter identifies Distributed Tables with local authentication enabled.
- Distributed Table Encryption Configuration: Identifies Distributed Tables (Cosmos DB accounts) based on whether they use customer-managed keys or provider-managed keys for encryption. By default, this Query Filter identifies Distributed Tables using provider-managed encryption.
- Distributed Table Without Network Traffic Restrictions: Identifies Distributed Tables (Cosmos DB accounts) that allow all network traffic or have
0.0.0.0configured in their firewall IP rules, which permits traffic from all Azure datacenters. - Database Instance Microsoft Entra-Only Authentication: Identifies Database Instances based on Microsoft Entra-only authentication configuration status. By default, this Query Filter identifies Database Instances that do not have Entra-only authentication configured.
- Database Instance Flexible Private Endpoint Connections: Identifies Azure Flexible Servers by Private Endpoint Connection status, configurable by engine type. By default, this Query Filter targets Azure MySQL Flexible Servers without private endpoints configured.
- Database Instance Firewall Allows Public Ingress: Identifies Database Instances with a firewall rule that allows public ingress. On Azure, a rule allows public ingress when its start IP is
0.0.0.0and its end IP is any address other than0.0.0.0. A rule spanning exactly0.0.0.0to0.0.0.0grants access only to Azure services and is not flagged.
Updated Insights
- Database Instance Without Log Auditing Enabled (MySQL): Updated and reformatted to align with CIS Microsoft Azure Database Services Benchmark v2.0.0 (Control 5.5).
- Database Instance Log Retention Below Threshold (PostgreSQL): Updated to identify Azure Database for PostgreSQL Flexible Servers where the
logfiles.retention_daysserver parameter is set to 3 days or fewer, supporting both legacylog_retention_daysand updatedlogfiles.retention_daysparameter names.
Updated Query Filters
- Database Instance With Setting Below Threshold log_retention_days (PostgreSQL): Updated to match both legacy
log_retention_daysand currentlogfiles.retention_daysparameter names using anORcondition when identifying PostgreSQL instances below the configured retention threshold.
Fixed
- Fixed an issue with incorrectly assigning MFA status to false for Alibaba Cloud user accounts even when MFA is enabled at the cloud level.
- Fixed an issue with the OCI onboarding script failing to update policies due to incorrect date format handling in the
version-datefield. The script now truncatesversion-dateto the date only format as required by the OCI CLI. - Fixed an issue where Azure harvesting was not completed on self-hosted deployments that use a proxy. Requests to Microsoft Graph now use proxy settings with no configuration changes required.
- Fixed a database error on the Insights page when filtering by
Insight Source = Customand then sorting a column.
Version 26.9.15
Software release date: September 15, 2026 | Release notes published: September 14, 2026
New Insights
- Cache Instance Not Using Customer Managed Key: Identifies Azure Cache for Redis instances that do not use Customer-Managed Keys (CMK) for encryption at rest.
- Cache Instance With Access Key Authentication Enabled: Identifies Azure Cache for Redis instances with access key authentication enabled, aligning with CIS Azure Database Services Benchmark v2.0.0 Control 2.9.
- Distributed Table With Public Network Access Enabled: Identifies Azure Cosmos DB instances with public network access enabled, aligned with CIS Controls v8.1.2 safeguard 4.4 and mapped to CMMC L1/L2, NIST SP 800-53 Rev. 5, and Microsoft Cloud Security Benchmark v1.
- Distributed Table Without Diagnostic Logging: Identifies Azure Cosmos DB accounts that do not have diagnostic logging enabled with the required log category (
allLogs). - Database Instance Without Microsoft Entra-Only Authentication (PostgreSQL): Identifies PostgreSQL Database Instances that do not have Microsoft Entra authentication configured as the only authentication method.
- Database Instance Public Network Access Enabled (SQL Server): Identifies SQL Server Database Instances with Public Network Access enabled.
- Database Instance Without Secure Transport Enabled (MySQL): Identifies Azure Database for MySQL Flexible Servers that do not have
require_secure_transportenabled. Mapped across NIST SP 800-53 Rev. 5, NIST SP 800-171, NIST CSF v2.0, CMMC Level 2, and Microsoft Cloud Security Benchmark v1 compliance packs.
Updated Insights
- Database Instance Without Connection Log Auditing Events (MySQL): Identifies Azure Database for MySQL Flexible Server instances where
audit_log_eventsdoes not containCONNECTIONorCONNECTION_V2, aligning with CIS Microsoft Azure Database Services Benchmark v2.0.0 Control 5.6. Mappings were added to NIST SP 800-53 Rev. 5 controls AU-2, AU-7, and AU-12, and to Microsoft Cloud Security Benchmark v1 controls LT-3, LT-4, and DS-7. - Database Instance TLS Version (MySQL Flexible Server): Updated Insight to align content, remediation steps, and formatting with CIS Microsoft Azure Database Services Benchmark v2.0.0 (Control 5.9). Added mappings to CIS Controls v8.1.2, NIST SP 800-53 Rev. 5, NIST SP 800-171 Rev. 2, NIST CSF v2.0, CMMC Level 2, and Microsoft Cloud Security Benchmark v1.
- Database Without Transparent Data Encryption (SQL Server): Renamed from Database without Transparent Data Encryption (SQL). Identifies Azure SQL Server Databases that do not have Transparent Data Encryption (TDE) enabled. Dedicated SQL Pool Databases are excluded.
- Database Instance Auditing Retention Below Threshold (SQL Server): Renamed from Database Instance Auditing Retention Below Threshold. Identifies Azure SQL Server Database Instances that have auditing enabled and an audit retention period of 90 days or less. A retention period of 0 (unlimited retention) is treated as compliant. Managed SQL instances are excluded.
New Query Filters
- Cache Instance Encryption Type: Identifies Cache Instances based on their encryption configuration (for example, Customer-Managed Key vs. Provider-Managed Key). By default, identifies Cache Instances using Provider-Managed Keys.
- Cache Instance Access Key Authentication Enabled: Identifies Azure Cache for Redis instances where access key authentication is enabled (
disableAccessKeyAuthenticationset to false). - Distributed Table Public Network Access: Identifies Distributed Tables (Azure Cosmos DB) with public network access enabled.
- Distributed Table Without Diagnostic Logging: Identifies Distributed Tables (Cosmos DB accounts) that do not have a specified diagnostic log category enabled. By default, checks for the
allLogscategory. - Database Instance Entra-Only Authentication: Identifies Database Instances based on whether they have Microsoft Entra-only authentication configured. By default, identifies Database Instances without Entra-only authentication configured.
Harvester Updates
- Azure Cache for Redis: Added support for harvesting Customer-Managed Key (CMK) encryption properties from Azure Cache for Redis Enterprise resources.
- Azure Diagnostic Settings: Added support for harvesting diagnostic settings for Azure Cosmos DB accounts (Microsoft.DocumentDb/databaseAccounts).
- Azure Database Instance: Added support for harvesting Microsoft Entra-only authentication status for Azure Database for PostgreSQL flexible servers.
- Azure Distributed Table (Cosmos DB): Added support for harvesting the
public_network_accessproperty for Azure Cosmos DB accounts.
Fixed
- Fixed an issue where Custom Insights could not be created using the Resources in Region Query Filter. The Query Filter now correctly restricts resource evaluation to resource types that support region-based querying.
- Fixed a pagination logic issue in the
AWS:StoredParameterHarvesterthat was exceeding the maximum of 50 parameters per request. Data chunking has been implemented to resolve the issue. - Fixed a false positive where OCI Exadata Database instances encrypted using an external customer-managed key (such as AWS KMS) were incorrectly flagged as non-compliant by the Resource Not Encrypted Or Encrypted With Cloud Managed Key Query Filter. The Query Filter now accounts for the
encryption_key_location_detailsfield that OCI sends when an external key provider is used, and correctly identifies these resources as compliant. - Fixed an issue where resource tag data could stop being updated in environments with very large numbers of resources, causing tags shown for those resources to become out of date.
- Fixed an issue where the Key Vault Exposed To Public Insight was not evaluating Azure resources despite the underlying Query Filter already supporting Azure cloud. Azure cloud has been added to the Insight’s supported clouds, and is now visible in the Supported Clouds subsection under Insight Details.
Version 26.9.8
Software release date: September 8, 2026 | Release notes published: September 7, 2026
New Features
- Released Kubernetes Scanner v5.4.0 with memory improvements. Internal components and their versions are available in the chart value file.
- View data using the
helm show values <chart name> | grep -E 'Name:|Version:'command. - Update using the
helm upgrade --installcommand referenced in the Kubernetes Scanner documentation.
- View data using the
Improved
- Added support for harvesting the
properties.updateChannelproperty for Azure Cache for Redis instances. - Added support for harvesting approved private endpoint connections by parsing
privateEndpointConnectionsfrom the Azure API response for Azure Cache for Redis instances.
New Insights
- Cache Instance Without Approved Private Link Connection: Detects Azure Cache for Redis instances without an approved Private Link connection.
- Cache Instance Update Channel Not Set to Stable: Identifies Azure Cache for Redis instances where the update channel is not set to
Stable. - Database Instance Encrypted using Cloud Managed Key Instead of Customer Managed Key (MySQL): Identifies MySQL Database Instances configured to use Cloud Managed Keys for encryption instead of Customer Managed Keys.
- Database Instance With Public Network Access Enabled (MySQL): Detects Azure Database for MySQL Flexible Servers with public network access enabled. Mapped across CIS, NIST, CMMC, and Azure Security Benchmark compliance packs.
- Database Instance Without Error Server Log File Enabled (MySQL): Identifies MySQL Database Instances that do not have the
error_server_log_fileserver parameter enabled for error logging. - Database Instance Without Minimum TLS Version (PostgreSQL): Identifies PostgreSQL Database Instances that do not have
ssl_min_protocol_versionset toTLSv1.2or higher. - Database Instance Minimum TLS Version (SQL Server): Identifies SQL Server Database Instances that do not enforce a Minimum TLS Version of 1.2 or higher.
Updated Insights
- Database Instance Without Customer Managed Key Encryption (SQL Server): This Insight has been renamed from Database Instance Encrypted using Cloud Managed Key Instead of Customer Managed Key (Azure SQL Server) and now excludes managed SQL instances.
- Key Vault Exposed To Public: Updated to include Azure cloud support.
New Query Filters
- Cache Instance Without Approved Private Endpoint Connection: Identifies Azure Cache for Redis instances based on whether they have an approved Private Link connection configured. By default, this Query Filter identifies instances without an approved Private Link connection.
- Cache Instance Update Channel Not Stable: Identifies Cache Instances where the update channel is not set to
Stableor is missing.
Updated Query Filters
- Database Instance Is Managed: Updated to identify database instances based on their managed instance status. By default, this Query Filter identifies managed instances.
Fixed
- Fixed an issue where a KMS key with automatic rotation enabled could be incorrectly flagged as “not rotating” after a temporary AWS API error during harvesting.
- Fixed an issue with the ‘list Insights’ operation not capturing total scanned resources, which resulted in ‘Total Resources’ being defaulted to 0 for all Insights in CSV exports.
- Fixed false positives in Azure Function App Insights App Service App Not Routed Through VNet Integration and Function App Without End-to-End TLS Encryption Enabled by excluding Consumption (Dynamic) plan apps, which do not support the required features.
- Fixed an issue where deleted GCP projects remained in Cloud Security instead of being automatically removed or paused.
- Fixed an issue where detaching AWS managed policies from IAM users or roles was not reflected after harvesting, causing stale Insight findings to persist.
- Fixed GCP DNS zone harvesting failures with
Cloud Permission Errorwhen a managed zone is deleted in GCP. Deleted zones are now correctly removed and remaining zones continue to harvest. - Azure container image vulnerability findings now populate correctly again after a Microsoft API change. CVE ID, severity, and package are included; Azure no longer supplies a CVSS score for these findings.
- Fixed query filter logic that caused accounts with a valid geo-blocking policy to still be flagged if they had any other non-compliant policy alongside it.
- Fixed an issue where harvesters for paused cloud accounts were still displayed.
- Fixed an authorization bypass where SSO configurations could be accessed or modified across organization boundaries.
- Fixed an issue where the filter information button incorrectly displayed “or” instead of “and” when filtering resources by Resource Tags.
SIEM (InsightIDR)
No updates released at this time.
Vulnerability Management (InsightVM)
Version 8.61.0
Software release date: September 28, 2026 | Release notes published: September 28, 2026
Improved:
- Add fingerprinting support for Microsoft 365 Copilot for Desktop. InsightVM now detects and inventories Microsoft 365 Copilot for Desktop as installed software, ensuring this application is visible in your asset data and included in vulnerability assessments.
- Fingerprinting support for Microsoft Office LTSC 2024 added. InsightVM now correctly identifies Microsoft Office LTSC 2024 as a distinct product, enabling vulnerability findings to be accurately reported for this Office edition and ensuring customers running LTSC deployments receive complete coverage.
- Updated fingerprinting to ensure detection of both the Stable and Extended Stable release channels of Microsoft Edge, providing more accurate software inventory and ensuring vulnerability assessments reflect the specific Edge variant deployed in your environment.
- Added fingerprinting support for Microsoft Teams, enabling the application to be accurately identified during scans and assessed for known vulnerabilities.
- Improved the Rapid7 Agent’s Windows filesystem walk tool to enhance reliability and coverage, reducing assessment failures on large filesystems and removing previous limitations on the scope of file searches during assessments — see the Insight Agent release notes for details.
Fixed:
- Resolved an issue where IBM WebSphere Application Server iFix packages associated with Direct Toolkit (DT) fixes were incorrectly reported as absent, resulting in false positive vulnerability findings for customers who had applied these patches.
- Updated fingerprinting to correctly detect Microsoft .NET Framework version 1.1 as installed software on Windows assets, ensuring that end-of-life findings for this legacy runtime are accurately reported and no longer missed during scans or agent assessments.
- Resolved an issue where third-party applications with the display name “Harmony” — such as Pencil9 Harmony — were incorrectly identified as Cleo Harmony, causing false positive findings for CVE-2024-55956 and CVE-2024-50623 on assets where Cleo Harmony was not installed.
- Resolved an issue where Mozilla Firefox (Standard edition) was not detected on assets where Firefox ESR was also installed, resulting in missing vulnerability findings for the Standard edition.
- Fixed an issue where MAC addresses were not being correctly parsed from Arista network devices during OS fingerprinting, which could impact asset correlation and inventory accuracy.
- Addressed an issue where multiple rules within the CIS Microsoft SQL Server 2019 v1.2.0 benchmark were generating false positive compliance findings on correctly configured SQL Server instances, ensuring policy assessment results accurately reflect the true compliance state.
- Resolved an issue with the fingerprinting logic for Ivanti Endpoint Manager Mobile (EPMM) where an incorrect pattern match prevented the product from being accurately detected on scanned assets, ensuring vulnerability assessments now correctly reflect the presence and version of Ivanti EPMM in your environment.
Version 8.60.0
Software release date: September 21, 2026 | Release notes published: September 18, 2026
Improved:
- Added support for TLS 1.3 as the preferred security protocol for console connections, providing improved connection performance and alignment with current security standards. TLS 1.2 remains fully supported and will be used automatically where TLS 1.3 is not available, ensuring no disruption to existing integrations or workflows.
- Added built-in policy support for CIS Apache Tomcat 11 Benchmark v1.1.0.
- Updated CIS Kubernetes (K8s) Benchmark support from v1.6.1 to v2.0.1.
Fixed:
- Addressed an issue where credential tests for Oracle databases configured with a Service Name could incorrectly report an authentication failure for valid credentials. Credential tests now accurately reflect authentication results.
- Fixed an issue in the Security Console UI where site schedule enable/disable states could display incorrectly when navigating across multiple pages. Schedule status is now displayed consistently and accurately.
- Resolved an issue with the Investigations feature that, under certain conditions, caused multiple scans to be initiated, having a detrimental impact on scan engine performance. This has been resolved to ensure the Investigate workflow operates as expected.
Version 8.59.0
Software release date: September 15, 2026 | Release notes published: September 14, 2026
Improved:
- Version 8.59.0 delivers a major upgrade to the in-built Spring Boot framework in the Security Console. This framework upgrade strengthens the overall security posture of the Security Console by keeping core application components current and aligned with modern security standards.
- Focused exclusively on the Spring Boot framework upgrade, version 8.59.0 does not include any new product features or defect fixes.
Version 8.58.0
Software release date: September 7, 2026 | Release notes published: September 9, 2026
New:
- Credentialed Pre-Port Discovery for Scan Templates. Scan templates now include a Use credentialed pre-port discovery option under Asset Discovery (off by default). When enabled, the scan engine retrieves open port information directly from each target using Scan Assistant, SSH, or Windows credentials — bypassing the network-based Nmap port scan for those assets. Targets without matching credentials or where authentication fails, fall back to standard Nmap scanning automatically, so no asset coverage is lost.
- See the blog post announcing this feature for more information.
Improved:
- Policy Content Updates:
- Added support for CIS Mozilla Firefox ESR GPO Benchmark v1.0.0
- CIS:
- Add Builtin Policy Content for CIS Microsoft Windows Server 2022 Benchmark from v4.0.0 to v5.1.0
- Add Builtin Policy Content for CIS Microsoft Windows Server 2025 Benchmark from v1.0.0 to v2.1.0
- Add Builtin Policy Content for CIS Amazon Linux 2 Benchmark from v3.0.0 to v4.0.0
Fixed:
- Addressed an issue where under certain conditions custom policy compliance scans were completing successfully but reporting zero integrated assets. This resulted in scan results not being recorded against any assets in the console. This has been resolved — assets are now correctly integrated following custom policy compliance scans.
- Fixed an issue that caused ARF Reports for CIS Benchmarks with Shell Command Checks Failing to Open. Asset Reporting Format (ARF) reports generated for CIS benchmarks that use shell command checks — such as CIS PostgreSQL 17 — were producing XML errors when opened in a browser, making the reports unusable. This has been resolved and ARF reports now open correctly.
- Console CLI Reset Password Command Failing. The command-line reset password function was failing with a database error, preventing administrators from resetting user passwords via the console CLI. This has been resolved and the reset password command now completes successfully.
- Discovery Connections Page Failing to Load. A discovery connection with a missing or incomplete status could prevent the entire Discovery Connections table from loading, leaving users unable to view or manage any connections. This has been resolved — the page now loads correctly regardless of individual connection state.
Nexpose
Nexpose Version 8.61.0
Software release date: September 28, 2026 | Release notes published: September 28, 2026
Improved:
- Add fingerprinting support for Microsoft 365 Copilot for Desktop. InsightVM now detects and inventories Microsoft 365 Copilot for Desktop as installed software, ensuring this application is visible in your asset data and included in vulnerability assessments.
- Fingerprinting support for Microsoft Office LTSC 2024 added. InsightVM now correctly identifies Microsoft Office LTSC 2024 as a distinct product, enabling vulnerability findings to be accurately reported for this Office edition and ensuring customers running LTSC deployments receive complete coverage.
- Updated fingerprinting to ensure detection of both the Stable and Extended Stable release channels of Microsoft Edge, providing more accurate software inventory and ensuring vulnerability assessments reflect the specific Edge variant deployed in your environment.
- Added fingerprinting support for Microsoft Teams, enabling the application to be accurately identified during scans and assessed for known vulnerabilities.
Fixed:
- Resolved an issue where IBM WebSphere Application Server iFix packages associated with Direct Toolkit (DT) fixes were incorrectly reported as absent, resulting in false positive vulnerability findings for customers who had applied these patches.
- Updated fingerprinting to correctly detect Microsoft .NET Framework version 1.1 as installed software on Windows assets, ensuring that end-of-life findings for this legacy runtime are accurately reported and no longer missed during scans or agent assessments.
- Resolved an issue where third-party applications with the display name “Harmony” — such as Pencil9 Harmony — were incorrectly identified as Cleo Harmony, causing false positive findings for CVE-2024-55956 and CVE-2024-50623 on assets where Cleo Harmony was not installed.
- Resolved an issue where Mozilla Firefox (Standard edition) was not detected on assets where Firefox ESR was also installed, resulting in missing vulnerability findings for the Standard edition.
- Fixed an issue where MAC addresses were not being correctly parsed from Arista network devices during OS fingerprinting, which could impact asset correlation and inventory accuracy.
- Addressed an issue where multiple rules within the CIS Microsoft SQL Server 2019 v1.2.0 benchmark were generating false positive compliance findings on correctly configured SQL Server instances, ensuring policy assessment results accurately reflect the true compliance state.
- Resolved an issue with the fingerprinting logic for Ivanti Endpoint Manager Mobile (EPMM) where an incorrect pattern match prevented the product from being accurately detected on scanned assets, ensuring vulnerability assessments now correctly reflect the presence and version of Ivanti EPMM in your environment.
Nexpose Version 8.60.0
Software release date: September 21, 2026 | Release notes published: September 18, 2026
Improved:
- Added support for TLS 1.3 as the preferred security protocol for console connections, providing improved connection performance and alignment with current security standards. TLS 1.2 remains fully supported and will be used automatically where TLS 1.3 is not available, ensuring no disruption to existing integrations or workflows.
- Policy Content Updates:
- Added built-in policy support for CIS Apache Tomcat 11 Benchmark v1.1.0.
- Updated CIS Kubernetes (K8s) Benchmark support from v1.6.1 to v2.0.1.
Fixed:
- Addressed an issue where credential tests for Oracle databases configured with a Service Name could incorrectly report an authentication failure for valid credentials. Credential tests now accurately reflect authentication results.
- Fixed an issue in the Security Console UI where site schedule enable/disable states could display incorrectly when navigating across multiple pages. Schedule status is now displayed consistently and accurately.
- Resolved an issue with the Investigations feature that, under certain conditions, caused multiple scans to be initiated, having a detrimental impact on scan engine performance. This has been resolved to ensure the Investigate workflow operates as expected.
Nexpose Version 8.59.0
Software release date: September 15, 2026 | Release notes published: September 14, 2026
Improved:
- Version 8.59.0 delivers a major upgrade to the in-built Spring Boot framework in the Security Console. This framework upgrade strengthens the overall security posture of the Security Console by keeping core application components current and aligned with modern security standards.
- Focused exclusively on the Spring Boot framework upgrade, version 8.59.0 does not include any new product features or defect fixes.
Nexpose Version 8.58.0
Software release date: September 7, 2026 | Release notes published: September 9, 2026
New:
- Credentialed Pre-Port Discovery for Scan Templates. Scan templates now include a Use credentialed pre-port discovery option under Asset Discovery (off by default). When enabled, the scan engine retrieves open port information directly from each target using Scan Assistant, SSH, or Windows credentials — bypassing the network-based Nmap port scan for those assets. Targets without matching credentials or where authentication fails, fall back to standard Nmap scanning automatically, so no asset coverage is lost.
- See the blog post announcing this feature for more information.
Improved:
- Policy Content Updates:
- Added support for CIS Mozilla Firefox ESR GPO Benchmark v1.0.0
- CIS:
- Add Builtin Policy Content for CIS Microsoft Windows Server 2022 Benchmark from v4.0.0 to v5.1.0
- Add Builtin Policy Content for CIS Microsoft Windows Server 2025 Benchmark from v1.0.0 to v2.1.0
- Add Builtin Policy Content for CIS Amazon Linux 2 Benchmark from v3.0.0 to v4.0.0
Fixed:
- Addressed an issue where under certain conditions custom policy compliance scans were completing successfully but reporting zero integrated assets. This resulted in scan results not being recorded against any assets in the console. This has been resolved — assets are now correctly integrated following custom policy compliance scans.
- Fixed an issue that caused ARF Reports for CIS Benchmarks with Shell Command Checks Failing to Open. Asset Reporting Format (ARF) reports generated for CIS benchmarks that use shell command checks — such as CIS PostgreSQL 17 — were producing XML errors when opened in a browser, making the reports unusable. This has been resolved and ARF reports now open correctly.
- Console CLI Reset Password Command Failing. The command-line reset password function was failing with a database error, preventing administrators from resetting user passwords via the console CLI. This has been resolved and the reset password command now completes successfully.
- Discovery Connections Page Failing to Load. A discovery connection with a missing or incomplete status could prevent the entire Discovery Connections table from loading, leaving users unable to view or manage any connections. This has been resolved — the page now loads correctly regardless of individual connection state.
Cyber GRC
No updates released at this time.
Digital Risk Protection (Threat Command)
No updates released at this time.
Rapid7 Agent (Insight Agent)
Version 4.1.3
Software release date: September 24, 2026 | Release notes published: September 24, 2026
New:
- Added Red Hat Enterprise Linux (RHEL) 10.2 compatibility for all supported architectures.
Improved:
- The Rapid7 Agent (Insight Agent) now records the outcome of filesystem discovery commands — including timeouts and non-zero exits — in the remote execution manifest, to ensure that timed-out or failed scans are no longer incorrectly interpreted as clean results by the vulnerability backend.
- Improvements to the Windows filesystem walk tool (
fswalk):- Increased the scan timeout from 10 minutes to 15 minutes to reduce failures on assets with large filesystems.
- Removed the limit on the number of search patterns that can be passed in a single scan, enabling broader file coverage during assessments.
Fixed:
- The Rapid7 Agent (Insight Agent) now correctly handles Windows volume usage data where the reported free space is greater than the total capacity.
- The Rapid7 Agent (Insight Agent) on Windows no longer enters an unrecoverable state when a slow job startup causes the beacon thread to miss its keepalive.
- The Windows local account snapshot no longer uses an incorrect argument order when calling the
NetUserEnumAPI, which previously caused inaccurate local account data to be collected. - The Rapid7 Agent (Insight Agent) real-time process monitor no longer crashes when it encounters process paths containing non-ASCII characters.
- Linux Rapid7 Agent (Insight Agent) instances no longer crash remote execution jobs due to an unhandled error when reading process information during a transient kernel state, which previously caused affected assets to stop reporting to the platform.
- Updated the following Python libraries used by the Rapid7 Agent (Insight Agent) to address vulnerabilities in previous versions:
| Library | Previous version | Updated version | CVEs addressed |
|---|---|---|---|
omnibus | 7.0.34 | 8.0.9 | CVE-2026-33210, CVE-2026-35611 |
pygments | 2.7.2 | 2.20.0 | CVE-2026-4539 |
setuptools | 80.9.0 | 83.0.0 | CVE-2026-59890 |
Resolved CVE-2026-89325
Software release date: September 15, 2026 | Release notes published: September 23, 2026
Resolved CVE-2026-89325, a local privilege escalation issue in which an assessment content check invoked an unqualified command that could be resolved from a user-writable directory in the machine PATH and executed by the Rapid7 Agent with SYSTEM privileges on Windows. This fix was delivered automatically to all Rapid7 Agents with content version 0.0.269.0, released on September 15, 2026, and requires no customer action.
Next-Generation Antivirus
No updates released at this time.
Ransomware Prevention
No updates released at this time.
Velociraptor
Version 0.74.4.38
Software release date: September 15, 2026 | Release notes published: September 15, 2026
Fixed:
-
The Rapid7 Velociraptor client now more efficiently manages idle network connections. This prevents memory from accumulating over time on endpoints that maintain long-running connections to the Rapid7 platform.
-
Updated the following third-party dependencies used by the Rapid7 Velociraptor client to address vulnerabilities in previous versions:
Library Previous version Updated version CVE addressed golang-jwt/jwtv3 (bare) v4.5.2 CVE-2025-30204 ulikunitz/xz0.5.11 0.5.14 CVE-2025-58058 russellhaering/goxmldsig1.5.0 1.6.0 CVE-2026-33487
Automation (InsightConnect)
No updates released at this time.
Rapid7 Network Sensor (Network Traffic Analysis)
No updates released at this time.