The complaint
The case is Flash Uplink LLC v. Rapid7, Inc., No. 7:26-cv-00401 (W.D. Tex.), filed October 2, 2026 in the Midland/Odessa Division and assigned to Judge David Counts. Flash Uplink, a Texas limited liability company based in Marshall, Texas, is represented by DeMatteo Law; its disclosure statement identifies Quest Patent Research Corporation as its corporate parent. The complaint alleges that Flash Uplink is the sole owner of U.S. Patent 8,230,497, Method of Identifying Software Vulnerabilities on a Computer System, issued July 24, 2012 and naming Andrew Patrick Norman, John Melvin Brawn, John P. Scrimsher, and Jonathan Griffin as inventors. Rapid7 is a Delaware corporation. Flash Uplink asserted the same patent against Aikido Security BV in the Eastern District of Texas on September 21, 2026, No. 2:26-cv-00861.
What claim 1 covers
Despite the patent's title, claim 1 is not a method claim. It covers a computer program stored on a non-transitory computer usable medium that, running under control of a processing means, identifies a software vulnerability by selecting one or more computer systems to be scanned, applying an interrogation program capable of exploiting a known software vulnerability to software on the computer system, and, if the vulnerability is exploited, operating the interrogation program to generate management information from which at least the identity of the affected computer system can be derived. The program must be capable of sending that information over a computer network, and the interrogation program must be further arranged to remediate the known vulnerability in response to identifying it.
The accused products
The complaint accuses a broad list of Rapid7 products, services, and integrations: Metasploit Pro and Metasploit Framework with their exploit, auxiliary, post-exploitation, MetaModule, task-chain, reporting, and remediation functions (naming the AD CS Workflows MetaModule, the DOUBLEPULSAR SMB and RDP modules, and the WDigest credential caching module); the Rapid7 Agent; InsightIDR; InsightVM; InsightConnect; InsightAppSec; Exposure Command, including Active Patching; Remediation Hub; Rapid7 Managed Detection and Response services; and integrations with third-party tools including BigFix, SCCM, Automox, Carbon Black, PAN-OS, Cisco FirePower, Cisco ISE, and Trend Micro Deep Security.
The complaint body does not map claim elements to any product. It says a preliminary chart attached as Exhibit A maps the elements of claim 1 to "an Accused Product," without naming which one. Claim 1 requires that the interrogation program itself be further arranged to remediate the known vulnerability. The complaint's description of the patent does not mention remediation, and its body does not say which product performs that step. Its product list credits remediation functions to Metasploit Pro and Metasploit Framework themselves and also names Exposure Command, including Active Patching, and Remediation Hub.
Theories, venue, and relief
The count alleges direct infringement under 35 U.S.C. 271, induced infringement under 271(b) through documentation, manuals, support, and marketing, and contributory infringement under 271(c), with knowledge of the patent "at least as of the date of this Complaint." The complaint does not allege that Rapid7 knew of the patent, or received actual notice of infringement, before the suit was filed. It alleges that Flash Uplink has at all times complied with the marking provisions of 35 U.S.C. 287 and, on information and belief, that any prior assignees and licensees also complied. Venue is pleaded under 28 U.S.C. 1400(b) based on Rapid7's office in Austin, Texas, within the Western District, and alleged acts of infringement in the district.
The prayer asks for a judgment of direct or indirect infringement, a judgment that the infringement is willful, damages of no less than a reasonable royalty, a permanent injunction under 35 U.S.C. 283, an exceptional-case finding and fees under 35 U.S.C. 285, and an accounting. No paragraph in the body of the complaint alleges willful infringement; the willfulness request appears only in the prayer. The complaint alleges irreparable harm absent an injunction. Google Patents lists an adjusted expiration date of September 24, 2031 for the patent; the complaint does not state an expiration date.
What to watch next
Watch for Rapid7's answer or any motion to dismiss, including any challenge to the willfulness request or the indirect infringement allegations, or to patent eligibility under 35 U.S.C. 101, any motion to transfer, and any petition for inter partes review. The case can end at any time by license, settlement, or dismissal.