SECURITYBLEEPING COMPUTER
vBulletin fixes critical pre-auth RCE flaw with public exploit
A critical vulnerability in vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code via template rendering. The flaw has a public exploit available.
Mentioned
Related Signal
Adjacent reporting
- Critical Marimo pre-auth RCE flaw now under active exploitation
- phpBB forum fixes auth bypass bug lurking for a decade
- Attackers pummel critical WordPress vuln to create all sorts of mischief
- GitHub fixes RCE flaw that gave access to millions of private repos
- Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks