Find notable cyber news and cases, enriched with sources, timelines, and signals.

VBulletin template engine unauthenticated RCE (CVE-2026-61511)

Vulnerability
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

Public exploit details for CVE-2026-61511 exposed a pre-authentication RCE in vBulletin's template engine, putting unpatched self-hosted forums at risk of code execution. The flaw affects vBulletin 6.2.1 and earlier and 6.1.6 and earlier, while 6.2.2 and branch-specific patches were released before disclosure. Cloud sites had already been patched, and no in-the-wild exploitation was confirmed at publication time.

Related Happenings

BRICKSTORM backdoor activity and GRIMBOLT replacement on appliances

Malware Activity
H score29 First: 18.02.2026 12:32 Last: 18.02.2026 12:32 Sources 1

About this happening: BRICKSTORM is a Golang backdoor used by PRC state-sponsored actors to keep long-term persistence on VMware vSphere, Windows, and appliance environments. ...

Timeline

  1. 27.07.2026 17:40 1 articles · 3h ago

    vBulletin releases 6.2.2 to fix template-engine remote code execution

    Mitigation Patch Update

    vBulletin released fixed version 6.2.2 on July 1 after issuing security patches for 6.2.1, 6.2.0, and 6.1.6, closing an unauthenticated remote code execution flaw in the template engine for self-hosted forums while Cloud sites were already patched.

    Show sources
  2. 27.07.2026 17:40 2 articles · 3h ago

    SSD publishes exploit details for unauthenticated vBulletin CVE-2026-61511

    Initial Disclosure

    SSD Secure Disclosure published public exploit details on July 27 for CVE-2026-61511, an unauthenticated remote code execution flaw in vBulletin's template engine that can reach PHP's `eval()` from the public `ajax/render/pagenav` route and a visitor-supplied `pagenav[pagenumber]` value. The advisory listed vBulletin 6.2.1 and earlier, and 6.1.6 and earlier, as affected, and said no confirmed in-the-wild attacks were available at publication time.

    Show sources