Public vBulletin exploit: unpatched forums remain at risk

Colleagues, I’d like to flag an important cybersecurity update: a public exploit for vBulletin has been released, and the vulnerability has been assigned CVE-2026-61511.
Key points:
• this is an unauthenticated RCE via the template engine;
• a patch for affected versions was issued in advance, but self-hosted instances that have not been updated remain exposed;
• according to the vendor, vBulletin Cloud is already protected;
• there is no confirmed active exploitation yet.
Why this matters: incidents like this once again show that delays in patching leave internet-facing services vulnerable.
Have you reviewed your installations? #cybersecurity #vBulletin #RCE #vulnerability


Latest comments
No comments yet.