logo

Critical vBulletin RCE Flaw Exposes Forum Servers to Unauthenticated Attacks

ID: ef6cdccc-3982-5c35-a1de-156bd3cd1032

STIX ID: report--ef6cdccc-3982-5c35-a1de-156bd3cd1032

Feed Name: ThreatCluster

Threat Score
80/100

Date Published: 2026-07-27

Date Updated: 2026-07-28

...
...

A critical unauthenticated remote code execution vulnerability (CVE-2026-61511) was disclosed in vBulletin affecting versions 6.2.1/6.1.6 and earlier; the flaw in vB5_Template_Runtime::runMaths() allows attackers to reach PHP eval() and execute arbitrary code. Public exploit details have been published and a patch is available—administrators are urged to apply updates immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.