Hackers are exploiting critical flaw in vBulletin forum software
ID: fbdc951f-69e7-50ce-8c63-fcaef5e26884
STIX ID: report--fbdc951f-69e7-50ce-8c63-fcaef5e26884
Feed Name: Bleeping Computer
Two critical vulnerabilities in vBulletin (CVE-2025-48827 and CVE-2025-48828) affecting versions 5.0.0–5.7.5 and 6.0.0–6.0.3 on PHP 8.1+ allow attackers to invoke protected methods via PHP Reflection and inject template code to achieve fully remote, unauthenticated code execution; a public PoC and exploitation attempts (targeting the ajax/api/ad/replaceAdTemplate endpoint) have been observed, and administrators are advised to apply the available patches or upgrade to vBulletin 6.1.1.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
