#9
The Hacker News
general
July 27, 2026 at 14:40 UTC
Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
By [email protected] (The Hacker News)
AI Summary
A public exploit was released on July 27 demonstrating how an unauthenticated HTTP request can reach PHP's eval() function in vBulletin versions 6.2.1 and earlier and 6.1.6 and earlier, enabling pre-authentication remote code execution with no user interaction required. Forum administrators on unpatched vBulletin instances are at immediate risk given the public availability of working exploit code.
Relevance score: 78.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →