logo

Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

ID: d9a5d47c-943f-57bf-98bb-64f302203480

STIX ID: report--d9a5d47c-943f-57bf-98bb-64f302203480

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-07-24

Date Updated: 2026-07-24

Author: [email protected] (The Hacker News)

...
...

Redis released multiple security updates after researchers published authenticated RCE proofs-of-concept targeting Redis versions 6.2.22, 7.4.9, 8.6.4, and 8.8.0. Two distinct exploitation paths were disclosed: a Streams shared-ownership (shared-NACK) double-free leading to arbitrary memory access and an out-of-bounds write in the RedisBloom TDigest RDB loader that can produce read/write primitives, libc leaks, and eventual system() invocation; vendor fixes are available for the affected branches and immediate mitigations include revoking RESTORE from unnecessary accounts and blocking untrusted network access. The report notes public PoCs but no confirmed in-the-wild exploitation as of July 24, 2026, and recommends upgrading to the fixed releases for the deployed branch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.