<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Public-Exploit on CuraSec</title><link>https://curasec.metacog.co.kr/tags/public-exploit/</link><description>Recent content in Public-Exploit on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 29 Jul 2026 13:07:14 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/public-exploit/index.xml" rel="self" type="application/rss+xml"/><item><title>vBulletin critical pre-auth RCE flaw has public exploit</title><link>https://curasec.metacog.co.kr/insights/2026-07-29-vbulletin-fixes-critical-pre-auth-rce-flaw-with-public-explo/</link><pubDate>Wed, 29 Jul 2026 13:07:14 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-29-vbulletin-fixes-critical-pre-auth-rce-flaw-with-public-explo/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Pre-auth RCE with a public exploit in vBulletin&amp;rsquo;s template renderer is actively exploitable right now — patch vBulletin to the vendor-released fixed version immediately if you run any internet-facing vBulletin instance.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> A public exploit for pre-auth PHP code execution means exploitation is likely in progress — sweep vBulletin access logs for anomalous template-rendering requests and hunt for web shells or unexpected PHP processes on any vBulletin host since the disclosure date.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Public Exploit for vBulletin Pre-Auth RCE Now Available</title><link>https://curasec.metacog.co.kr/insights/2026-07-28-public-exploit-released-for-patched-vbulletin-pre-auth-code/</link><pubDate>Tue, 28 Jul 2026 13:01:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-28-public-exploit-released-for-patched-vbulletin-pre-auth-code/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> A public exploit now makes unauthenticated code execution against vBulletin 6.2.1 and earlier trivially accessible to any attacker. Patch to the fixed release immediately; if no patch is available for your branch, take the instance offline or block external access until patched.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> With a public exploit in the wild, opportunistic scanning and exploitation attempts are likely imminent. Build or tune web application attack detections for anomalous unauthenticated POST requests to vBulletin PHP endpoints and PHP child-process spawning indicative of eval() abuse.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>WordPress Core 'wp2shell' RCE flaws get public exploits</title><link>https://curasec.metacog.co.kr/insights/2026-07-19-wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch/</link><pubDate>Sun, 19 Jul 2026 12:05:51 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-19-wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Public exploits for critical WordPress Core RCE make this urgent regardless of absent KEV/EPSS data — update WordPress Core to the latest patched release immediately and verify any managed hosting environments are also updated.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> No IOCs or TTPs are provided to hunt on now, but given public exploits exist for a widely-deployed web platform, build or tune detections for WordPress exploit traffic (e.g., anomalous POST patterns, webshell indicators in web access logs) before active campaigns arrive.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> This is an engineering-track issue, not board-level — confirm your team has inventoried WordPress instances across the estate and that patching is tracked to completion this week.&lt;/li>
&lt;/ul></description></item></channel></rss>