vBulletin Patches Critical Unauthenticated RCE Flaw With Active Public Exploit
vBulletin has released fixes for a critical vulnerability, tracked as CVE-2026-61511, affecting versions 5.x through 5.7.5 and 6.x through 6.2.1. The flaw allows unauthenticated attackers to execute arbitrary PHP code by sending a crafted request to the public AJAX template rendering endpoint ajax/render/pagenav, bypassing weak input validation in the runMaths() function to reach PHP's eval(). No login or user interaction is required, making the vulnerability exploitable by anyone with internet access to an affected forum. A public proof-of-concept exploit already exists, raising concerns about imminent widespread scanning and exploitation. Site administrators are urged to upgrade to vBulletin 6.2.2 or apply Patch Level 1 immediately to mitigate the risk.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in