HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Pre‑Auth RCE (CVE‑2026‑61511) in vBulletin Allows Unauthenticated Code Execution

A pre‑authentication remote code execution vulnerability (CVE‑2026‑61511) in vBulletin 5.x/6.x lets attackers run arbitrary PHP via the ajax/render endpoint. Organizations must patch quickly and capture remediation evidence to stay audit‑ready.

LiveThreat™ Intelligence · 📅 July 28, 2026· 📰 bleepingcomputer.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

vBulletin Critical Pre‑Auth RCE (CVE‑2026‑61511) Exposes Unpatched Forum Servers

What Happened — A pre‑authentication remote code execution flaw (CVE‑2026‑61511) was disclosed in vBulletin 5.x and 6.x. The vulnerability resides in the runMaths() function, which fails to sanitize input before passing it to PHP’s eval(). A public proof‑of‑concept allows attackers to send a crafted request to ajax/render/[template] and execute arbitrary PHP code on the server.

Why It Matters for Compliance & Audit Readiness

  • The flaw bypasses the “no‑unauthenticated access” control that SOC 2’s CC6.1 – System Operations expects, highlighting gaps in patch‑management and secure‑development processes.
  • Continuous evidence of remediation (patch deployment, WAF rule changes) is essential to demonstrate due diligence during a SOC 2 audit.

Who Is Affected — Online communities, gaming portals, support sites, and any organization that runs a public‑facing vBulletin forum (spanning tech, retail, media, and government sectors).

Recommended Actions

  • Upgrade to vBulletin 6.2.2 (or later) immediately; back‑port patches to older 6.x releases where possible.
  • Apply a web‑application firewall rule to block the vulnerable ajax/render/* endpoint until patched.
  • Document the patch‑management activity in your SOC 2 change‑management logs and capture evidence for audit reviewers.

Technical Notes

  • Attack vector: unauthenticated HTTP request to ajax/render/[template].
  • CVSS (pre‑release): 9.8 (Critical).
  • Exploited component: PHP eval() via insufficient input sanitization in runMaths().
  • Public PoC: available, raising the likelihood of automated scanning.

Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/vbulletin-fixes-critical-pre-auth-rce-flaw-with-public-exploit/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →