WEDNESDAY, JULY 29, 2026 48° E  /  GLOBAL TECH · SUMMARISED SUBSCRIBE
AI, business, devices, policy — global tech, summarised every 30 minutes.
Security · 1h ago

Critical vBulletin RCE flaw lets attackers execute code without authentication

By Meridian48 News Desk · Summarised from DEV Community ·

A critical unauthenticated remote code execution vulnerability (CVE-2026-61511) in vBulletin 5.x and 6.x allows attackers to execute arbitrary PHP code via a crafted request to the public AJAX template endpoint. The flaw, rated high severity, bypasses math validation in runMaths() and reaches PHP's eval() function. A public proof-of-concept exists, and scanning activity is expected to increase.

Meridian48 take
While vBulletin has released patches, the public PoC means unpatched forums are at immediate risk of takeover and data theft.
Read the full reporting
vBulletin CVE-2026-61511: Unauthenticated RCE via Public AJAX Template to `eval()` →
DEV Community
vbulletinrce
More security briefs
Go deeper on security
AllAIStartupsBusinessDevicesPolicySecurityDev ToolsPakistan