Rapid7 Completes BSI C5 Type 2 Examination: Stronger Cloud Security for DACH Organizations

2026-03-24T19:23:53Z2e071543d6e43e69c0a6f9a1ca4bd85ce3eab8d6f76522d0613ae0931bb55f8d
ARMOAVideoBSI C5CNAPPCVECitrixDACHExposure CommandFreePBXGainsightMetasploitNetScalerRapid7 LabsSAML IDPType 2 attestationXSScloud securitycomplianceinformation disclosureout-of-bounds readthreat landscapevulnerability management

What happened

This Rapid7 blog batch covers product compliance and security research: Rapid7 completed BSI C5 Type 2 attestation for the Rapid7 Command Platform (important for DACH procurement). Rapid7 Labs disclosed and analyzed multiple vulnerabilities: a critical Citrix NetScaler ADC/Gateway out-of-bounds read (CVE-2026-3055, CVSS 9.3; advisory also references CVE-2026-4368) affecting SAML IDP configurations, new Metasploit modules for CVE-2026-29058 and CVE-2025-64328, and Gainsight Assist vulnerabilities (CVE-2026-31381 information disclosure and CVE-2026-31382 reflected XSS) that have been fixed. The稿

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
2e071543d6e43e69c0a6f9a1ca4bd85ce3eab8d6f76522d0613ae0931bb55f8d
Enrichment time
2026-03-24T19:23:53Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.