Critical vBulletin RCE Flaw Exposes Forum Servers to Unauthenticated Attacks
ID: ef6cdccc-3982-5c35-a1de-156bd3cd1032
STIX ID: report--ef6cdccc-3982-5c35-a1de-156bd3cd1032
Feed Name: ThreatCluster
Threat Score
A critical unauthenticated remote code execution vulnerability (CVE-2026-61511) was disclosed in vBulletin affecting versions 6.2.1/6.1.6 and earlier; the flaw in vB5_Template_Runtime::runMaths() allows attackers to reach PHP eval() and execute arbitrary code. Public exploit details have been published and a patch is available—administrators are urged to apply updates immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
