A public proof-of-concept has been released for CVE-2026-61511, a pre-authentication Remote Code Execution (RCE) vulnerability in vBulletin, allowing unauthenticated attackers to execute PHP on servers via a math-parsing flaw. The vulnerability affects vBulletin versions 6.2.1 and earlier, as well as 6.1.6 and earlier. vBulletin has resolved the issue in version 6.2.2. The flaw involves the runMaths() method, which improperly filters input, and researchers have confirmed no current in-the-wild exploits. It is crucial for affected users to upgrade or apply security patches to mitigate the risk.
PoC Released for Severe vBulletin RCE Flaw CVE-2026-61511
CyberSIXT Evidence Panel
Article by CyberSIXT