vBulletin fixes critical pre-auth RCE flaw with public exploit
PoC publicvBulletinOur summary
vBulletin has issued a security update to resolve a severe remote code execution vulnerability that allows unauthenticated attackers to run arbitrary PHP code. The flaw, identified as CVE-2026-61511, impacts versions in the 5.x and 6.x branches up to 5.7.5 and 6.2.1, respectively. A proof-of-concept exploit is already available, increasing the risk of attacks on vulnerable systems. Users are strongly advised to upgrade to the latest patched versions.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.