🔥 この記事の詳細
2026-08-11 更新
B
今週中

Rapid7のソフトウェア「Velociraptor」において、15件の脆弱性

脆弱性🌐 英語ソース
🔢 CVECVE-2026-64954CVE-2026-18972CVE-2026-18860
📅 2026-08-11📰 csirt_it
📌 一言でいうと
Rapid7のソフトウェア「Velociraptor」において、15件の脆弱性が発見されました。このうち1件は「クリティカル」、6件は「高」の深刻度となっており、認証回避や権限昇格、データの整合性侵害などのリスクがあります。影響を受けるバージョンは0.77.2未満であり、最新バージョンへのアップデートが推奨されています。
🔍該当判定
  • Rapid7社の製品『Velociraptor』を導入して利用している
  • 社内PCやサーバーに『Velociraptor』のソフトをインストールしている
  • 利用している『Velociraptor』のバージョンが 0.77.2 より古い
上記いずれにも該当しない → 静観でOK
該当時の対応
影響を受けるVelociraptorをバージョン0.77.2以降にアップデートしてください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Rapid7 Velociraptor 脆弱性対応について

お疲れさまです。Rapid7 Velociraptorに関する脆弱性情報共有です。

■ 概要
Velociraptorにおいて、認証回避や権限昇格を可能にする15件の脆弱性が報告されました。うち1件はクリティカル、6件が高深刻度であり、悪用された場合はシステム上のデータや設定が改ざんされる恐れがあります。

■ 影響範囲
- 対象製品: Rapid7 Velociraptor
- 対象バージョン: 0.77.2 未満

■ 対応手順
1. 現在利用しているVelociraptorのバージョンを確認してください。
2. 0.77.2 未満である場合は、速やかに最新バージョンへアップデートを適用してください。

■ 参考情報
- Rapid7 公式セキュリティアドバイザリ

対応優先度: 高
対応期限: 速やかに
Subject: [Security Advisory] Rapid7 Velociraptor Vulnerability Remediation

Dear IT/Security Team,

We are sharing critical vulnerability information regarding Rapid7 Velociraptor.

■ Overview
Fifteen vulnerabilities have been identified in Velociraptor, including one critical and six high-severity flaws. These could allow an attacker to bypass authentication/authorization and compromise the integrity of data and configurations.

■ Scope
- Product: Rapid7 Velociraptor
- Affected Versions: Prior to 0.77.2

■ Remediation Steps
1. Verify the current version of Velociraptor in use.
2. Update to version 0.77.2 or later immediately if the current version is affected.

■ Reference
- Rapid7 Official Security Bulletins

Priority: High
Deadline: Immediate