< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-07-24T12:28:27+05:30

Kimi K3 Agents Identify Redis Zero-Day Vulnerabilities Leading to RCE Exploits

Researchers discovered two Redis zero-day vulnerabilities enabling remote code execution (RCE) through the RESTORE command, leading to critical security updates. The exploits, identified by Kimi K3 agents, affect multiple Redis versions and require immediate patching to prevent exploitation.

Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0.

All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloom module. Redis says the underlying memory flaws may lead to remote code execution.

Redis 6.2.23, 7.2.15, and 7.4.10

Read original article

*** END OF TRANSMISSION ***