CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

RediShell: Critical Remote Code Execution Vulnerability (CVE-2025-49844) in Redis, 10 CVSS score

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 1406

As cited

Copy frozen at (site build).

vulnerabilities

RediShell: Critical Remote Code Execution Vulnerability (CVE-2025-49844) in Redis, 10 CVSS score

Wiz Research has identified a critical remote code execution vulnerability in Redis (CVE-2025-49844) that stems from a bug present for 13 years across all versions of the software. Redis is used in approximately 75% of cloud environments, making this flaw potentially widespread.

Why it matters: Organizations running Redis in production should treat this as urgent: a CVSS 10 remote code execution vulnerability affects a foundational technology in most cloud deployments and requires immediate patching or mitigation.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

RediShell: Critical Remote Code Execution Vulnerability (CVE-2025-49844) in Redis, 10 CVSS score

Wiz Research disclosed a critical remote code execution vulnerability in Redis that has existed for 13 years across all versions of the software. The flaw, tracked as CVE-2025-49844 with a CVSS score of 9.9, affects a database system used in approximately 75% of cloud environments.

Why it matters: Redis users operating in cloud environments need to prioritize patching immediately, as the vulnerability enables remote code execution on a widely deployed infrastructure component.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

RediShell: Critical Remote Code Execution Vulnerability (CVE-2025-49844) in Redis, 10 CVSS score

Wiz Research disclosed a critical remote code execution vulnerability in Redis that has existed for 13 years across all versions of the software. The flaw, tracked as CVE-2025-49844 with a CVSS score of 9.9, affects a database system used in approximately 75% of cloud environments.

Why it matters: Redis users operating in cloud environments need to prioritize patching immediately, as the vulnerability enables remote code execution on a widely deployed infrastructure component.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary