Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-07-28 ยท updated: 2026-08-18 ยท tags: [] ยท confidence: not-rated ยท severity: not-rated ยท affected_sectors: [] ยท au_impact: false

CVE-2026-61511

Overview

CVE-2026-61511 is a pre-authentication remote code execution vulnerability in vBulletin forum software. An unauthenticated attacker can reach PHP's eval() function in vBulletin versions 6.2.1, 6.1.6, and earlier, achieving full remote code execution with no account required.

Technical Details

  • Attack vector: Network (unauthenticated)
  • Impact: Remote code execution via PHP eval() reachability
  • Exploit published: 2026-07-27 by SSD Secure Disclosure
  • In-the-wild exploitation: None confirmed as of 2026-07-27
  • KEV status: Not yet added to CISA's Known Exploited Vulnerabilities catalogue

Timeline

Date Event
Late June 2026 vBulletin patches the flaw
2026-07-01 vBulletin 6.2.2 released with fix
2026-07-27 SSD Secure Disclosure publishes exploit details
2026-07-28 Digest coverage

Mitigation

  • Self-hosted instances: Upgrade to vBulletin 6.2.2 immediately
  • vBulletin Cloud: Instances are already protected

Related

References