Act
archived
vBulletin critical pre-auth RCE flaw has public exploit
- Engineer — Act: Pre-auth RCE with a public exploit in vBulletin’s template renderer is actively exploitable right now — patch vBulletin to the vendor-released fixed version immediately if you run any internet-facing vBulletin instance.
- SOC/IR — Act: A public exploit for pre-auth PHP code execution means exploitation is likely in progress — sweep vBulletin access logs for anomalous template-rendering requests and hunt for web shells or unexpected PHP processes on any vBulletin host since the disclosure date.
- Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.