securityonline.info 7/27/2026, 10:11:57 AM · external

PoC Released for Severe vBulletin RCE Flaw CVE-2026-61511

PoC Released for Severe vBulletin RCE Flaw CVE-2026-61511
CyberSIXT Evidence Panel
Primary Source forum.vbulletin.com
CISA KEV Not in KEV
Patch Patch Status Unknown

A public proof-of-concept has been released for CVE-2026-61511, a pre-authentication Remote Code Execution (RCE) vulnerability in vBulletin, allowing unauthenticated attackers to execute PHP on servers via a math-parsing flaw. The vulnerability affects vBulletin versions 6.2.1 and earlier, as well as 6.1.6 and earlier. vBulletin has resolved the issue in version 6.2.2. The flaw involves the runMaths() method, which improperly filters input, and researchers have confirmed no current in-the-wild exploits. It is crucial for affected users to upgrade or apply security patches to mitigate the risk.

View Primary Source Via securityonline.info

Article by CyberSIXT