CVE Tools
Back to feed
PoC public vBulletin rce web-app

Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw

The Hacker News·By The Hacker News··3 min read
CVE Tools coverage

A public exploit has been shared for a patched remote code execution vulnerability in vBulletin, allowing attackers to execute arbitrary code without authentication. The flaw affects versions up to 6.2.1 and 6.1.6, with patches available since late June 2026. Despite the availability of fixes, unpatched self-hosted installations remain at risk. The vulnerability resides in the template engine’s handling of inline math expressions, enabling malicious users to bypass filters and trigger PHP's eval() function. While no active exploitation has been confirmed yet, the release of the proof-of-concept increases the likelihood of real-world attacks.