September 2026 Release Notes
The Command Platform release notes include information about what’s new, which are updated monthly, and improvements and fixes, which are updated weekly.
Last updated: September 8, 2026
What’s New
Learn about new features across the Command Platform. These features were released over the past month and are available now:
Attack surface
Your attack surface is comprised of all of the potential entry points that attackers could exploit across your systems, applications, and networks. Developing knowledge of your attack surface is a key goal in improving your company’s security posture.
- Communicate remediation priorities faster with AI-summarized reports (Surface Command, Exposure Command)
- Unify more remediation activity with CrowdStrike data in Remediation Hub (Surface Command, Exposure Command)
- Endpoint process start events now include user identity context
Communicate remediation priorities faster with AI-summarized reports
Remediation Hub now includes a Top Remediations Report with AI Summary, making it easier to share clear, actionable remediation context with asset owners and other stakeholders. The AI-generated summary that appears in Remediation Hub is now available directly in the report, giving stakeholders consistent insight into what needs to be fixed, why it matters, and what to do next without requiring manual explanation.
With this update in Risk > Remediation Hub, you can:
Share context alongside each remediation, including potential impact and recommended next steps. Provide stakeholders with a consistent experience between what teams view in the product and what they receive in reports. Reduce manual follow-up by delivering clear, self-explanatory remediation context directly in the report. Export reports in HTML or CSV format to meet different stakeholder needs.
Impacted offerings:
- Surface Command
- Exposure Command
Unify more remediation activity with CrowdStrike data in Remediation Hub
Remediation Hub now surfaces remediation recommendations from CrowdStrike, giving you a more unified view of remediation activity across your environment. Customers using the latest CrowdStrike connector for Rapid7 Attack Surface Management will see CrowdStrike findings directly alongside remediation data from other sources, reducing the need to switch between tools to prioritize and act on findings.
With this update in Risk > Remediation Hub, you can:
- View CrowdStrike remediation recommendations directly within Remediation Hub.
- Prioritize CrowdStrike findings alongside data from other remediation sources in a single workflow.
- Reduce context switching with a more unified remediation experience across environments.
Impacted offerings:
- Surface Command
- Exposure Command
Endpoint process start events now include user identity context
Process start events now automatically include the associated LDAP or Active Directory (AD) user, connecting endpoint activity with identity context across detection and investigation workflows. Previously, users needed to manually correlate endpoint activity with identity data to determine which user executed a process. Process start events now include a top-level user field and associated user RRN, allowing alerts and investigations to surface the attributed user automatically.
This enhancement in Alerts and Investigations helps you:
- View attributed user details directly in alerts and investigations.
- Correlate process activity with the user’s endpoint, cloud, and identity activity.
- See relevant user activity in investigation timelines and user pages.
- Investigate endpoint activity associated with users who have elevated directory privileges.
This additional identity context reduces manual correlation during triage and helps analysts more quickly understand who is associated with endpoint activity.
Impacted Offerings:
- SIEM
Threat
A threat is any potential event or action that could exploit vulnerabilities in a system, causing harm to assets, data, or operations. Threats can originate from various sources, including malicious actors, natural disasters, or unintentional human errors.
- Access continuous threat hunting visibility with MDR Threat Hunting
- Monitor data collection health with the Environment Health Dashboard
Access continuous threat hunting visibility with MDR Threat Hunting
MDR customers can now view every completed threat hunt Rapid7 performs on their behalf directly in the Command Platform. The new Threat Hunts page brings proactive hunting activity out of monthly reports and into a continuously updated, self-service experience, giving you and your Cybersecurity Advisor a shared, always-current record of hunting work.
With this capability in Response & Remediation > Threat Hunts, you can:
- Browse a searchable list of all completed hunts, with summary metric cards for quick status checks.
- Explore full hunt detail pages, including the Threat Brief, description, recommended actions, indicators of compromise (IOCs), and the queries used.
- Replay hunt queries directly in Log Search with the original time range pre-populated.
- Generate PDF or HTML reports on demand or on a schedule at both the individual hunt level and across a configurable time period.
Impacted offerings:
- MDR
Monitor data collection health with the Environment Health Dashboard
You can now monitor the health of your data collection environment from a single, dedicated page. The Environment Health Dashboard consolidates health metrics across your agents, collectors, event sources, network sensors, orchestrators, honeypots, scan engines, and data exporters, giving you a clear, current picture of your data pipeline without having to navigate across multiple pages.
With this capability in Data Connectors > Environment Health, you can:
- View key counts for each data source type by state, including online, offline, and stale, in the KPI bar and state bar chart.
- Identify known issues across your data sources in the issue feed, sorted by severity, with direct links to relevant documentation.
- Review collector resource utilization, including memory, CPU, and storage, in the resourcing table to catch capacity issues before they affect collection.
- Quickly identify event sources that are stopped or have been inactive for more than 24 hours.
- Export dashboard data as a PDF or HTML report.
Impacted offerings:
- SIEM (MDR)
- Incident Command
Cyber GRC
- Automate evidence collection across the employee lifecycle with the Workday integration
- Create tasks faster with a guided, step-by-step workflow
- Validate SSO configurations automatically with Authentication Provider URI checks
Automate evidence collection across the employee lifecycle with the Workday integration
The Workday integration in Rapid7 Cyber GRC now covers the full employee lifecycle, from onboarding through offboarding, so access review controls can pull automated evidence without manual collection.
With this update, you can:
- Automatically generate access review evidence tied to employment status changes in Workday.
- Reduce the manual effort required to prepare for user access reviews.
- Keep access review controls current as employees join, change roles, or leave the organization.
Create tasks faster with a guided, step-by-step workflow
Task creation in Rapid7 Cyber GRC now uses a guided, step-by-step flow instead of a single long form, making it faster and less error-prone to create new tasks.
Validate SSO configurations automatically with Authentication Provider URI checks
OIDC and SAML configurations in Rapid7 Cyber GRC now validate the Authentication Provider URI automatically, helping teams catch SSO misconfigurations before they cause login issues.
Improvements and Fixes
Keep track of improvements and fixes to core technology.
Application Security (InsightAppSec) and AppSpider
Version 7.5.029
Software release date: September 9, 2026 | Release notes published: September 9, 2026
New Features:
- AI Vulnerability Validator: Expanded Module Support - Integrated AWS Bedrock LLM verification for LDAP Injection findings, expanding the AI Vulnerability Validator suite alongside existing Blind SQL, Blind NoSQL, SQL Injection, and Remote File Inclusion (RFI) validation models to automatically evaluate and filter false positives.
- AI Validator FP Transparency Logging - Enabled automated generation of assessment log/report artifacts when the AI Vulnerability Validator is enabled, documenting every finding flagged as a false positive and excluded from scan results.
- ALF v2.1.1 Infrastructure Upgrade - Upgraded the Application Layer Framework (ALF) to v2.1.1, introducing native One-Time Password (OTP) support without manual hook setups, expanded ALF logging visibility, and optimized default configuration parameters.
- Technology Detection Evidence Context - Technology Detection vulnerability findings now incorporate detailed “Detection Method” and “Match Details” telemetry forwarded directly from R7Crawler.
Improved:
- AppSec Scan Engine
- Dynamic Memory Management - Optimized memory caching mechanisms during scanning to resolve memory allocation issues and prevent scan failures caused by insufficient memory.
- ASP.NET Core Configuration Leak Detection - Upgraded the Predictable Resource Location module to identify exposed ASP.NET Core / .NET Core configuration files located in web roots that leak sensitive credentials and environment secrets.
- Session Strength False Positives - Corrected module testing logic to ignore non-authorization tokens, eliminating false positive session strength findings.
- FrontPage/SharePoint Clean-up - Remediated false positive triggers affecting non-vulnerable Microsoft SharePoint environments.
- Per-URL Failure Tracking - Enhanced consecutive error handling by introducing per-URL failure tracking and configurable controls to block repeatedly failing URLs from stalling engine runs.
- Runtime Security Upgrades - Updated the installed .NET 8 runtime component from 8.0.29 to 8.0.30.
- Attack Data Defs - Updated analyze profiles to detect recent Drupal iterations and resolved edge cases during meta tag evaluations.
- R7 Crawler
- Browser & Driver Upgrades - Upgraded R7Crawler to Chromium version 151.0.7922.34 and bumped Selenium ChromeDriver to version 152.0.7977.64.
- Partial Page Load Support - Requests that time out waiting for total page load but achieve
DOMContentLoadedare logged and processed as valid partial-load states. - Link Ingestion & Coverage - Optimized processing of discovered
hreftargets to increase overall crawl depth during Chromium-driven scans. - Bot Detection Evasion - Refined
navigator.webdrivermasking controls to improve bot avoidance on protected targets. - Session Check Logic - Automatically suppresses
isLoggedIndetection routines on pages that fail to load.
Fixed:
- AppSec Scan Engine
- Technology Detection Validation Scans - Fixed inconsistent behavior during validation scans by adding full validation scan support to the Technology Detection module.
Attack Surface Management (Surface Command)
Version 1.0.938
Software release date: September 1, 2026 | Release notes published: September 8, 2026
Fixed:
- The Test Connection button is now available only for connectors supporting this feature.
- The Widget filter editor now retains lone Timeframe filters for trend widgets upon saving.
Connectors
The following connectors were updated in the Extension Library since the previous release. Connector updates are published independently and may have been available before this release date.
Updated Connectors
- Anthropic: Added import of organizations, organization users, roles, and groups from the Anthropic Compliance API.
- BlackBerry Cylance: Updated broken documentation link in requirements. BlackBerry Cylance is now part of Arctic Wolf Aurora EDR.
- Check Point Harmony Endpoint:
- 401 authentication errors no longer occur; connector now re-authenticates when the session token expires.
- 400 errors when running the test function no longer occur.
- Cisco Duo: Added proper reference to CiscoDuoPhone.
- Crowdstrike Falcon:
- New
Host Groupssetting: Only import Devices (and their Alerts, Vulnerabilities, and Software) that belong to the given Host Groups (comma-separated). Requires theHost Groups: Readpermission. - CrowdstrikeSoftwareInstallation: Import failures caused by Windows installation paths ending in a backslash no longer occur.
- New
- Devo SIEM: Scope data control configuration items per connection profile to prevent cross-profile key collisions
- FortiClient EMS: Shorten file path for refdocs to fix packaging error.
- Google Drive: Scoped data control configuration items per connection profile to prevent cross-profile key collisions.
- Google Workspace: Scoped data control configuration items per connection profile to prevent cross-profile key collisions.
- Infoblox NIOS DDI: Fixed 500 error on superhost endpoint by removing unsupported fields and deferring paging to subsequent requests.
- Ivanti Neurons for ITSM: Shortened workflow file path to fix packaging error.
- ManageEngine Endpoint Central: Remove sample data files with paths exceeding packaging limit.
- ManageEngine OpManager: Shortened file path for functions module to fix packaging error.
- Microsoft 365: Shortened file paths to fix packaging error.
- Microsoft AD Certificate Services: Fixed large-CA imports.
- Microsoft Defender EASM: Shortened file path for functions module to fix packaging error.
- Microsoft Defender for IoT: Shortened file path for functions module to fix packaging error.
- Microsoft Intune:
- Added MicrosoftIntuneGroup type.
- New
Group Type(s)setting added. NeedsGroup.Read.AllandGroupMember.Read.Allpermission. - Software installations are now collected by default via a single whole-tenant report export, replacing the per-app device fan-out that could not complete on large tenants. On a tenant with 39,180 applications and 1,665,687 installations, the software import feed now completes in under 40 minutes, where it previously ran for days without finishing.
- Bound the number of in-flight export jobs so the per-device export strategy drains instead of growing on every pass.
- Stream the software export through disk so memory use stays flat regardless of tenant size.
- Write export scratch files to a fixed cache directory instead of a temporary one.
- Fix software import feed failures caused by Microsoft Graph throttling by adding a fixed backoff and retry strategy for managed-device requests.
- Improve software export performance with bulk processing and streaming.
- Add access token caching to reduce redundant authentication calls.
- Microsoft SQL: Scoped data control configuration items per connection profile to prevent cross-profile key collisions.
- Mimecast: Fixed packaging issue.
- Okta: Added OktaRole type and the standard administrator roles.
- Palo Alto Cortex Xpanse: Shortened file path for functions module to fix packaging error.
- PostgreSQL: Scoped data control configuration items per connection profile to prevent cross-profile key collisions.
- SSH File Transfer Protocol (SFTP): Scoped data control configuration items per connection profile to prevent cross-profile key collisions.
- Shodan: Scoped data control configuration items per connection profile to prevent cross-profile key collisions.
- Slack:
- Replaced the slack-bolt dependency with slack_sdk.
- Workflow posting message changes.
- Snowflake: Schema validation improvements.
- Splunk: Scope data control configuration items per connection profile to prevent cross-profile key collisions.
- TOPdesk:
- Added new
TOPdeskIncidenttype and incident data import. - Added
Import Incidents?setting to enable/disable incident import (default: disabled). - Added
Import Only Active Incidents?setting to limit imports to non-closed incidents (default: enabled). - Requires read permission on the
Call Management→First-line callsandSecond-line callsmodules on the TOPdesk API Token when incident import is enabled.
- Added new
Cloud Security (InsightCloudSec)
No updates released at this time.
Mimics Infrastructure as Code (IaC) Scanning Tool
No updates released at this time.
SIEM (InsightIDR)
No updates released at this time.
Vulnerability Management (InsightVM)
No updates released at this time.
Nexpose
No updates released at this time.
Cyber GRC
No updates released at this time.
Digital Risk Protection (Threat Command)
No updates released at this time.
Rapid7 Agent (Insight Agent)
No updates released at this time.
Next-Generation Antivirus
No updates released at this time.
Ransomware Prevention
No updates released at this time.
Velociraptor
No updates released at this time.
Automation (InsightConnect)
No updates released at this time.
Rapid7 Network Sensor (Network Traffic Analysis)
No updates released at this time.