PoC public Redis 6.2.22 zero-day Redis 7.4.9 Redis rce
Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say
CVE Tools coverage
Researchers have published proof-of-concept (PoC) remote code execution (RCE) exploits targeting multiple Redis versions, including 6.2.22, 7.4.9, 8.6.4, and 8.8.0. These vulnerabilities stem from memory corruption issues in Redis Streams and the RedisBloom module. Redis has issued seven security updates on July 23 to address these flaws. Users should upgrade to the latest stable versions—6.2.23, 7.2.15, 7.4.10, 8.2.8, 8.4.5, 8.6.5, and 8.8.1—to mitigate risks. Until patches are applied, administrators are advised to restrict access to the RESTORE command and block untrusted network connections.