CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3153

As cited

Copy frozen at (site build).

vulnerabilities

Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

Redis released seven security updates on July 23, 2024, following the disclosure of authenticated remote code execution exploits affecting versions 6.2.22, 7.4.9, 8.6.4, and 8.8.0. The exploits leverage the RESTORE command in combination with other features such as EVAL, Streams groups, or the RedisBloom module to achieve code execution through underlying memory vulnerabilities.

Why it matters: Organizations running unpatched Redis instances with authentication enabled should prioritize upgrading to patched versions (6.2.23, 7.2.15, 7.4.10, or later) to prevent authenticated attackers from achieving remote code execution.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

Redis released security updates on July 23, 2026 following researcher disclosures of authenticated remote code execution (RCE) flaws affecting multiple versions. The vulnerabilities require specific commands like RESTORE and, in some cases, EVAL or additional modules to exploit. The underlying memory corruption issues could allow attackers to execute code on vulnerable Redis instances.

Why it matters: Organizations running Redis 6.2.22, 7.4.9, 8.6.4, or 8.8.0 must verify they have applied patches immediately, as authenticated attackers can achieve RCE through known command chains.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary