VBulletin template engine unauthenticated RCE (CVE-2026-61511)
Vulnerability
Summary
Hide ▲
Show ▼
Public exploit details for CVE-2026-61511 exposed a pre-authentication RCE in vBulletin's template engine, putting unpatched self-hosted forums at risk of code execution. The flaw affects vBulletin 6.2.1 and earlier and 6.1.6 and earlier, while 6.2.2 and branch-specific patches were released before disclosure. Cloud sites had already been patched, and no in-the-wild exploitation was confirmed at publication time.
Related Happenings
BRICKSTORM backdoor activity and GRIMBOLT replacement on appliances
Malware Activity
H score29
First: 18.02.2026 12:32
Last: 18.02.2026 12:32
Sources 1
About this happening:
BRICKSTORM is a Golang backdoor used by PRC state-sponsored actors to keep long-term persistence on VMware vSphere, Windows, and appliance environments. ...
BRICKSTORM backdoor activity and GRIMBOLT replacement on appliances
Malware ActivityAbout this happening: BRICKSTORM is a Golang backdoor used by PRC state-sponsored actors to keep long-term persistence on VMware vSphere, Windows, and appliance environments. ...
Timeline
-
27.07.2026 17:40 1 articles · 3h ago
vBulletin releases 6.2.2 to fix template-engine remote code execution
Mitigation Patch UpdatevBulletin released fixed version 6.2.2 on July 1 after issuing security patches for 6.2.1, 6.2.0, and 6.1.6, closing an unauthenticated remote code execution flaw in the template engine for self-hosted forums while Cloud sites were already patched.
Show sources
- Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw — thehackernews.com — 27.07.2026 17:40
-
27.07.2026 17:40 2 articles · 3h ago
SSD publishes exploit details for unauthenticated vBulletin CVE-2026-61511
Initial DisclosureSSD Secure Disclosure published public exploit details on July 27 for CVE-2026-61511, an unauthenticated remote code execution flaw in vBulletin's template engine that can reach PHP's `eval()` from the public `ajax/render/pagenav` route and a visitor-supplied `pagenav[pagenumber]` value. The advisory listed vBulletin 6.2.1 and earlier, and 6.1.6 and earlier, as affected, and said no confirmed in-the-wild attacks were available at publication time.
Show sources
- Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw — thehackernews.com — 27.07.2026 17:40
- Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw — thehackernews.com — 27.07.2026 17:40