logo

New Kimi K3 AI Agent Uncovers 0-Day Exploits in Redis Server

ID: 80d25672-f0c4-536c-8815-a73e90755d82

STIX ID: report--80d25672-f0c4-536c-8815-a73e90755d82

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

Author: Guru Baran

...
...

Research tied to the Kimi K3 AI agent discloses multiple authenticated RCE vectors in Redis: a shared-NACK double-free affecting 6.2.22, 7.4.9, and 8.6.4, and a TDigest heap overflow in the bundled RedisBloom module on 8.8.0. Both attack paths require commonly enabled admin commands (EVAL, RESTORE, XGROUP) and valid credentials; the issues can yield host-level shells without crashing the service. The report urges rapid patching, command restriction/ACLs, network isolation, credential hygiene, module auditing, and monitoring while warning that 8.8.0 is not automatically safe until RedisBloom is fixed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.