Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-07-27 ยท updated: 2026-08-18 ยท tags: [] ยท confidence: not-rated ยท affected_sectors: [] ยท au_impact: false

Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw (Cve 2026 61511 Vbulletin Preauth Rce)

Summary

SSD Secure Disclosure published exploit details on 2026-07-27 demonstrating how an unauthenticated attacker can reach PHP's eval() function in vBulletin 6.2.1/6.1.6 and earlier, achieving remote code execution with no account required.

Key Details

Field Detail
CVE Cve 2026 61511 Vbulletin Preauth Rce
Product vBulletin
Versions affected โ‰ค6.2.1, โ‰ค6.1.6
Patched version 6.2.2
Exploit publisher SSD Secure Disclosure
Exploit release date 2026-07-27
Patch available since Late June / 2026-07-01
In-the-wild exploitation None confirmed
KEV status Not yet listed

Risk Assessment

  • Self-hosted instances running unpatched vBulletin are at immediate risk now that a public exploit is available
  • vBulletin Cloud instances are already protected
  • The four-week gap between patch and exploit publication gave administrators a reasonable window, but any unpatched instances are now critically exposed

Mitigation

Upgrade to vBulletin 6.2.2 immediately. Monitor for signs of exploitation targeting vBulletin endpoints.

Related

References