Censys Scan Finds 98.82% of 8500 Exposed REDCap Instances on Legacy Versions
Censys telemetry reveals systemic exposure of REDCap research platforms with the majority on versions actively exploited by UNC6508 for long-dwell credential theft. GTIG reporting and version distribution data together show how architectural tolerance for legacy code creates persistent risk to health and scientific datasets. Remediation requires both patching and architectural separation of database layers.
Censys mapped 8500 internet-facing REDCap deployments across 100 countries with 40% in the US. GTIG reporting documents UNC6508 probing legacy versions that Vanderbilt's architecture explicitly permits to run alongside current releases. Attackers harvested credentials on initial access then waited one year before using them for internal network traversal and data exfiltration from medical and military research organizations.
The evidence trail centers on version telemetry rather than disclosed CVEs. 16.0.17 dominates at 30% followed by 16.1.4 and 16.0.15. GTIG could not confirm initial vector but observed repeated scanning of outdated instances. This matches the documented design choice allowing side-by-side legacy execution, a configuration choice that directly enables the observed dwell time.
Widespread exposure repeats the pattern seen with other medical research platforms where public accessibility is chosen over network segmentation. The vendor recommendation to isolate the database behind a firewall is routinely ignored, creating a single point of failure for sensitive health datasets. State actors have demonstrated both the reconnaissance and the patience to exploit it.
Organizations must inventory all instances immediately, enforce 17.x upgrades, and remove direct internet exposure. Continued legacy tolerance will sustain the current access pipeline for espionage campaigns targeting academic and healthcare networks.
Censys: Fewer than 15% of current legacy REDCap instances will reach version 17.1.3 by December 2025.
Sources (2)
- [1]Primary Source(https://www.securityweek.com/majority-of-internet-accessible-redcap-servers-outdated/)
- [2]Supporting Source(https://cloud.google.com/blog/topics/threat-intelligence/unc6508-redcap-targeting)