type: incident ยท created: 2026-07-27 ยท updated: 2026-08-18 ยท tags: [] ยท confidence: not-rated ยท affected_sectors: [] ยท au_impact: false
Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw (Cve 2026 61511 Vbulletin Preauth Rce)
Summary
SSD Secure Disclosure published exploit details on 2026-07-27 demonstrating how an unauthenticated attacker can reach PHP's eval() function in vBulletin 6.2.1/6.1.6 and earlier, achieving remote code execution with no account required.
Key Details
| Field | Detail |
|---|---|
| CVE | Cve 2026 61511 Vbulletin Preauth Rce |
| Product | vBulletin |
| Versions affected | โค6.2.1, โค6.1.6 |
| Patched version | 6.2.2 |
| Exploit publisher | SSD Secure Disclosure |
| Exploit release date | 2026-07-27 |
| Patch available since | Late June / 2026-07-01 |
| In-the-wild exploitation | None confirmed |
| KEV status | Not yet listed |
Risk Assessment
- Self-hosted instances running unpatched vBulletin are at immediate risk now that a public exploit is available
- vBulletin Cloud instances are already protected
- The four-week gap between patch and exploit publication gave administrators a reasonable window, but any unpatched instances are now critically exposed
Mitigation
Upgrade to vBulletin 6.2.2 immediately. Monitor for signs of exploitation targeting vBulletin endpoints.