logo

Redis warns of critical flaw impacting thousands of instances

ID: 8b5b3bd9-14f4-5fab-bb1c-33d4b2ff44e1

STIX ID: report--8b5b3bd9-14f4-5fab-bb1c-33d4b2ff44e1

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-10-06

Date Updated: 2026-07-18

Author: Sergiu Gatlan

...
...

The Redis security team and Wiz disclosed CVE-2025-49844 (RediShell), a critical Lua use-after-free vulnerability enabling authenticated attackers to escape the Lua sandbox and achieve remote code execution on Redis hosts; patches are available for many releases, and researchers reported roughly 330,000 Internet-exposed instances (about 60,000 without authentication). Administrators are urged to apply updates, disable Lua or enable authentication, run Redis as non-root, and implement network controls to mitigate exploitation and subsequent abuse such as credential theft, cryptomining, lateral movement, and persistent backdoors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.