Critical vBulletin Flaw Lets Unauthenticated Attackers Execute PHP Code Remotely
ID: 9e6cc323-c440-521b-9086-486cf11a342d
STIX ID: report--9e6cc323-c440-521b-9086-486cf11a342d
Feed Name: cybersecurityNews.com
vBulletin patched CVE-2026-61511, a critical unauthenticated RCE in /includes/vb5/template/runtime.php (vB5_Template_Runtime::runMaths) affecting vBulletin 6.2.1/6.1.6 and earlier; attackers can abuse ajax/render/[template] (for example pagenav[pagenumber]) to inject expressions evaluated by PHP, potentially enabling command execution. Administrators are advised to update to 6.2.2 or apply vendor patches and monitor web logs and signs of compromise (new PHP files, unexpected outbound connections, altered templates, unauthorized admin accounts).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
