CVE Tools
Back to feed
PoC public vBulletin rce web-app

vBulletin fixes critical pre-auth RCE flaw with public exploit

BleepingComputer·By Bill Toulas··2 min read
CVE Tools coverage

vBulletin has issued a security update to resolve a severe remote code execution vulnerability that allows unauthenticated attackers to run arbitrary PHP code. The flaw, identified as CVE-2026-61511, impacts versions in the 5.x and 6.x branches up to 5.7.5 and 6.2.1, respectively. A proof-of-concept exploit is already available, increasing the risk of attacks on vulnerable systems. Users are strongly advised to upgrade to the latest patched versions.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store