bleeping-computer · Crawled Jul 28, 2026

vBulletin fixes critical pre-auth RCE flaw with public exploit

Read original article ↗

AI Summary

A critical pre-authentication remote code execution (RCE) vulnerability, CVE-2026-61511, has been identified in vBulletin forum software versions 5.x and 6.x prior to 5.7.5 and 6.2.1. The flaw stems from improper input sanitization in the 'runMaths()' function, which allows unauthenticated attackers to execute arbitrary PHP code via the 'ajax/render/[template]' endpoint. A public proof-of-concept exploit has been released, increasing the risk of widespread exploitation against unpatched internet-facing servers. vBulletin has released patches in version 6.2.2 and backported fixes for select 6.x versions, but no fix is available for the 5.x branch.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.