importantSYS.SOURCE: The Hacker News• 2026-07-24T12:28:27+05:30
Kimi K3 Agents Identify Redis Zero-Day Vulnerabilities Leading to RCE Exploits
Researchers discovered two Redis zero-day vulnerabilities enabling remote code execution (RCE) through the RESTORE command, leading to critical security updates. The exploits, identified by Kimi K3 agents, affect multiple Redis versions and require immediate patching to prevent exploitation.
Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0.
All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloom module. Redis says the underlying memory flaws may lead to remote code execution.
Redis 6.2.23, 7.2.15, and 7.4.10
*** END OF TRANSMISSION ***