The record
Written from the 1 report below. Nothing here is unsourced.
- Public exploit details have been released for CVE-2026-61511, a critical pre-authentication remote code execution flaw affecting vBulletin versions 5.x through 5.7.5 and 6.x through 6.2.1.
- The vulnerability is an eval injection in the vB5_Template_Runtime::runMaths() method, allowing unauthenticated attackers to execute arbitrary code.
- CVSS is 9.8; no confirmed in-the-wild exploitation has been observed yet, and the flaw does not appear on CISA's KEV list. vBulletin has released patches — users must apply the patch for their branch or upgrade to v6.2.2.
- The risk is concentrated among self-hosted vBulletin deployments that have not yet patched.
- Administrators are advised to review POST requests to routestring=ajax/render/pagenav with unusually long or operator-heavy pagenav[pagenumber] values as a workaround.
What to watch next
- Patch vBulletin immediately — upgrade to 6.2.2 or branch-specific fix.
- Monitor WAF/proxy logs for suspicious ajax/render/pagenav POSTs.
- Confirm no in-the-wild exploitation before relaxing patch urgency.
Why it matters3
Who is affected first and what likely follows, with a direction and a horizon. Extracted from the reports, never invented.
- vBulletin self-hosted administrators patch required· immediate
- Self-hosted vBulletin 5.x/6.x deployments remote code execution risk· days
- Security/vulnerability management teams monitoring burden increase· days
Coverage1
1 report
English national1
Filed from India ×1, United States ×1
Named CISA · Egidio Romano · SSD Secure Disclosure · vBulletin
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
