Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
PoC publicvBulletinOur summary
A public exploit has been shared for a patched remote code execution vulnerability in vBulletin, allowing attackers to execute arbitrary code without authentication. The flaw affects versions up to 6.2.1 and 6.1.6, with patches available since late June 2026. Despite the availability of fixes, unpatched self-hosted installations remain at risk. The vulnerability resides in the template engine’s handling of inline math expressions, enabling malicious users to bypass filters and trigger PHP's eval() function. While no active exploitation has been confirmed yet, the release of the proof-of-concept increases the likelihood of real-world attacks.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.