The record
Written from the 1 report below. Nothing here is unsourced.
- On July 23, 2026, Redis issued seven security updates after public proof-of-concept exploits emerged for authenticated remote code execution flaws in both the core Streams module and the RedisBloom probabilistic-data-module.
- The two highlighted CVEs (CVE-2026-25589 and CVE-2026-25243) both stem from improper validation of serialized values passed through the Redis RESTORE command, CVSS 8.8, and affect Redis 6.2.22, 7.4.9, 8.6.4, 8.8.0 and RedisBloom bundled in 8.8.0.
- The vulnerabilities are serious but require an attacker to already be authenticated and have permission to execute RESTORE, which limits blast radius to environments with weak ACLs or tenant-shared credentials.
- No in-the-wild exploitation is reported yet, though public PoCs raise the probability of opportunistic abuse.
- Vendors covering this uniformly advise upgrading to fixed releases, revoking RESTORE from accounts that do not strictly need it, and blocking untrusted network access to Redis instances.
What to watch next
- Upgrade Redis and RedisBloom to fixed versions across dev/staging/prod.
- Revoke RESTORE command privileges from non-admin application accounts.
- Restrict network exposure of Redis to trusted subnets and enforce TLS + authentication.
- Monitor for unusual RESTORE command usage in audit logs.
Why it matters4
Who is affected first and what likely follows, with a direction and a horizon. Extracted from the reports, never invented.
- Redis and RedisBloom deployments (including managed Redis services) patch required· days
- Organizations exposing Redis to untrusted networks or using shared credentials rce risk· immediate
- Authenticated application accounts issued against Redis privilege review required· days
- Security engineering and SOC teams monitoring tuning· days
Coverage1
1 report
English national1
Filed from United States ×2, India ×1
Named India · Redisbloom · Bera Buddies · Chaofan Shou · CISA · Kimi K3 Agents · Redis
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
