Home / Jul 28, 2026 / Story
0
#9 The Hacker News general July 27, 2026 at 14:40 UTC

Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw

By [email protected] (The Hacker News)

AI Summary

A public exploit was released on July 27 demonstrating how an unauthenticated HTTP request can reach PHP's eval() function in vBulletin versions 6.2.1 and earlier and 6.1.6 and earlier, enabling pre-authentication remote code execution with no user interaction required. Forum administrators on unpatched vBulletin instances are at immediate risk given the public availability of working exploit code.

Relevance score: 78.0/100

# More from July 28