Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-07-25 ยท updated: 2026-07-25 ยท tags: [incident, zero-day, sector-technology, technique] ยท confidence: high ยท affected_sectors: [technology] ยท au_impact: false

Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit

Redis shipped seven security releases on 23 July 2026 after researchers published authenticated RCE PoCs for multiple versions. Flaws include use-after-free in Streams shared-NACK and out-of-bounds writes in RedisBloom/TDigest modules. Multiple branches affected (6.2.x through 8.8.x).

Overview

Attribute Detail
Date 2026-07-24 (disclosure), 2026-07-23 (patches)
Product Redis (multiple branches: 6.2.x through 8.8.x)
Discoverer Kimi K3 AI agents
Vulnerability Types Use-after-free, Out-of-bounds writes, RCE
Patches 7 security releases

Vulnerability Details

  • Use-after-free in Streams shared-NACK: Memory corruption in Redis stream processing
  • Out-of-bounds writes in RedisBloom: Memory safety issues in the RedisBloom module
  • Out-of-bounds writes in TDigest: Similar issues in the TDigest module
  • Multiple authenticated RCE PoCs published against various versions

Significance

This case, alongside Nodebb Patches Eight Ai Found Flaws Exposing Admin Access And Private Chats, demonstrates the growing trend of AI agents conducting vulnerability research autonomously. Kimi K3 agents not only found the zero-days but also built functional RCE exploits, representing a significant milestone in AI-assisted security research.

Related Pages