A critical vulnerability has been identified in Redis, known as CVE-2026-66373, which involves a Remote Code Execution (RCE) risk stemming from a double-free bug in the RESTORE command. This flaw allows an authenticated attacker to potentially corrupt memory and execute arbitrary code within the Redis server process. The vulnerability has a CVSS score of 7.5 and affects all Redis versions prior to 8.8.0.
There are currently no confirmed instances of exploitation in the wild, and the issue has been patched in Redis version 8.8.0. Users are strongly advised to update to this version immediately to safeguard their systems.