securityonline.info 7/30/2026, 8:21:32 AM · external

CVE-2026-66373: Redis RCE Proof-of-Concept Publicly Disclosed

CVE-2026-66373: Redis RCE Proof-of-Concept Publicly Disclosed
CyberSIXT Evidence Panel
Primary Source github.com
CISA KEV Not in KEV
Patch Patch Status Unknown

A critical vulnerability has been identified in Redis, known as CVE-2026-66373, which involves a Remote Code Execution (RCE) risk stemming from a double-free bug in the RESTORE command. This flaw allows an authenticated attacker to potentially corrupt memory and execute arbitrary code within the Redis server process. The vulnerability has a CVSS score of 7.5 and affects all Redis versions prior to 8.8.0.

There are currently no confirmed instances of exploitation in the wild, and the issue has been patched in Redis version 8.8.0. Users are strongly advised to update to this version immediately to safeguard their systems.

View Primary Source Via securityonline.info

Article by CyberSIXT