PoC public vBulletin rce web-app
vBulletin fixes critical pre-auth RCE flaw with public exploit
CVE Tools coverage
vBulletin has issued a security update to resolve a severe remote code execution vulnerability that allows unauthenticated attackers to run arbitrary PHP code. The flaw, identified as CVE-2026-61511, impacts versions in the 5.x and 6.x branches up to 5.7.5 and 6.2.1, respectively. A proof-of-concept exploit is already available, increasing the risk of attacks on vulnerable systems. Users are strongly advised to upgrade to the latest patched versions.