type: cve ยท created: 2026-07-28 ยท updated: 2026-08-18 ยท tags: [] ยท confidence: not-rated ยท severity: not-rated ยท affected_sectors: [] ยท au_impact: false
CVE-2026-61511
Overview
CVE-2026-61511 is a pre-authentication remote code execution vulnerability in vBulletin forum software. An unauthenticated attacker can reach PHP's eval() function in vBulletin versions 6.2.1, 6.1.6, and earlier, achieving full remote code execution with no account required.
Technical Details
- Attack vector: Network (unauthenticated)
- Impact: Remote code execution via PHP
eval()reachability - Exploit published: 2026-07-27 by SSD Secure Disclosure
- In-the-wild exploitation: None confirmed as of 2026-07-27
- KEV status: Not yet added to CISA's Known Exploited Vulnerabilities catalogue
Timeline
| Date | Event |
|---|---|
| Late June 2026 | vBulletin patches the flaw |
| 2026-07-01 | vBulletin 6.2.2 released with fix |
| 2026-07-27 | SSD Secure Disclosure publishes exploit details |
| 2026-07-28 | Digest coverage |
Mitigation
- Self-hosted instances: Upgrade to vBulletin 6.2.2 immediately
- vBulletin Cloud: Instances are already protected
Related
References
- The Hacker News โ 2026-07-27 coverage
- SSD Secure Disclosure โ Exploit publication