Security · 1h ago
Critical vBulletin RCE flaw lets attackers execute code without authentication
A critical unauthenticated remote code execution vulnerability (CVE-2026-61511) in vBulletin 5.x and 6.x allows attackers to execute arbitrary PHP code via a crafted request to the public AJAX template endpoint. The flaw, rated high severity, bypasses math validation in runMaths() and reaches PHP's eval() function. A public proof-of-concept exists, and scanning activity is expected to increase.
Meridian48 take
While vBulletin has released patches, the public PoC means unpatched forums are at immediate risk of takeover and data theft.
Read the full reporting
vBulletin CVE-2026-61511: Unauthenticated RCE via Public AJAX Template to `eval()` →
DEV Community
vbulletinrce