CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Remote Code Execution Vulnerability in ImunifyAV/AI-bolit

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

A remote code execution (RCE) flaw in the AI-bolit malware scanning component of ImunifyAV and Imunify360, used by millions of Linux-hosted websites, could allow attackers to compromise hosting environments. The vulnerability stems from improper validation of function names during deobfuscation of PHP files. The flaw affects versions prior to 32.7.4.0 and has been patched, but no CVE identifier has been assigned. The vulnerability is particularly concerning due to the widespread use of ImunifyAV in shared hosting environments, potentially enabling full server takeovers if the scanner runs with elevated privileges.

Timeline

  1. 13.11.2025 21:04 1 articles · 23h ago

    RCE flaw in ImunifyAV/AI-bolit disclosed and patched

    A remote code execution (RCE) flaw in the AI-bolit malware scanning component of ImunifyAV and Imunify360, used by millions of Linux-hosted websites, was disclosed and patched. The vulnerability stems from improper validation of function names during deobfuscation of PHP files. The flaw affects versions prior to 32.7.4.0 and has been patched, but no CVE identifier has been assigned. The vulnerability is particularly concerning due to the widespread use of ImunifyAV in shared hosting environments, potentially enabling full server takeovers if the scanner runs with elevated privileges.

    Show sources

Information Snippets