CVE-2026-6948: RAPID7 Velociraptor
Medium severity, CVSS 4.9. EPSS: 0.4% chance of exploitation in the next 30 days.
Velociraptor versions prior to 0.76.4 contain a resource exhaustion vulnerability in the server's agent control channel. This allows a compromised or rogue Velociraptor client to crash the server via out-of-memory (OOM) by sending crafted messages through the normal client communication channel.
Affected products
- RAPID7 Velociraptor: before 0.76.4 (fixed in 0.76.4); before 0.75.9 (fixed in 0.75.9)
Published 2026-05-04. Last modified 2026-06-17.