CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

vBulletin fixes critical pre-auth RCE flaw with public exploit

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3382

As cited

Copy frozen at (site build).

vulnerabilities

vBulletin fixes critical pre-auth RCE flaw with public exploit

vBulletin released a patch for a critical pre-authentication remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code via template rendering. The flaw affects the forum software and carries a public exploit.

Why it matters: Organizations running vBulletin forums must apply the patch immediately, as unauthenticated attackers can exploit this publicly disclosed vulnerability to gain code execution on affected systems.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary