Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Vulnerability CVE-2026-61511
A public exploit was released for a previously patched vBulletin pre-authentication remote code execution vulnerability (CVE-2026-61511), affecting versions 6.2.1 and earlier, with patches available since late June 2026. Unpatched self-hosted installations remain at risk despite the vendor's fixes and the exploit targeting a now-patched flaw.
Public exploit details released on July 27 show how an unauthenticated request can reach PHP's eval() function inside vBulletin and execute code on an unpatched forum server. The attack requires no account, administrative access, or interaction from another user.
SSD Secure Disclosure lists vBulletin 6.2.1 and earlier, and 6.1.6 and earlier, as affected, but does not give a lower version
*** END OF TRANSMISSION ***