CVE Tools
Back to feed
PoC public vBulletin rce web-app

vBulletin fixes critical pre-auth RCE flaw with public exploit

BleepingComputer·By Bill Toulas··2 min read
CVE Tools coverage

vBulletin has issued a security update to resolve a severe remote code execution vulnerability that allows unauthenticated attackers to run arbitrary PHP code. The flaw, identified as CVE-2026-61511, impacts versions in the 5.x and 6.x branches up to 5.7.5 and 6.2.1, respectively. A proof-of-concept exploit is already available, increasing the risk of attacks on vulnerable systems. Users are strongly advised to upgrade to the latest patched versions.