type: incident ยท created: 2026-07-25 ยท updated: 2026-07-25 ยท tags: [incident, zero-day, sector-technology, technique] ยท confidence: high ยท affected_sectors: [technology] ยท au_impact: false
Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit
Redis shipped seven security releases on 23 July 2026 after researchers published authenticated RCE PoCs for multiple versions. Flaws include use-after-free in Streams shared-NACK and out-of-bounds writes in RedisBloom/TDigest modules. Multiple branches affected (6.2.x through 8.8.x).
Overview
| Attribute | Detail |
|---|---|
| Date | 2026-07-24 (disclosure), 2026-07-23 (patches) |
| Product | Redis (multiple branches: 6.2.x through 8.8.x) |
| Discoverer | Kimi K3 AI agents |
| Vulnerability Types | Use-after-free, Out-of-bounds writes, RCE |
| Patches | 7 security releases |
Vulnerability Details
- Use-after-free in Streams shared-NACK: Memory corruption in Redis stream processing
- Out-of-bounds writes in RedisBloom: Memory safety issues in the RedisBloom module
- Out-of-bounds writes in TDigest: Similar issues in the TDigest module
- Multiple authenticated RCE PoCs published against various versions
Significance
This case, alongside Nodebb Patches Eight Ai Found Flaws Exposing Admin Access And Private Chats, demonstrates the growing trend of AI agents conducting vulnerability research autonomously. Kimi K3 agents not only found the zero-days but also built functional RCE exploits, representing a significant milestone in AI-assisted security research.
Related Pages
- Nodebb Patches Eight Ai Found Flaws Exposing Admin Access And Private Chats โ AI pentest agents found 8 flaws in NodeBB