:

VBULLETIN PATCHES CRITICAL PRE-AUTH RCE FLAW

SECURITY DESK1 MIN READ
TUE, JUL 28, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

vBulletin has released a patch for a critical remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code. A public exploit for the flaw is already in circulation.

The vulnerability exists in vBulletin's template rendering system, enabling attackers to bypass authentication requirements and execute arbitrary code on affected servers. The flaw requires no user interaction or credentials to exploit. The security issue impacts multiple versions of the forum software. vBulletin has released updates to address the vulnerability, though the availability of a public exploit increases the risk of widespread attacks. Administrators of vBulletin installations should apply patches immediately. The pre-authentication nature of the vulnerability makes it particularly dangerous, as attackers can target systems without needing valid user accounts. Users should verify their vBulletin installation is running the latest patched version and monitor their systems for signs of compromise. Organizations running vBulletin should treat this as a priority security issue.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

The U.S. Cybersecurity and Infrastructure Security Agency has issued an urgent directive requiring federal agencies to mitigate actively exploited vulnerabilities in IBM Langflow, N-central, and Apache Tomcat within three days.

5H AGOSecurity Desk

The Department of Homeland Security is attempting to obtain Signal group chat messages from plaintiffs in a free-speech lawsuit against the agency. The move has raised concerns about using legal discovery to surveil encrypted communications.

11H AGOIndustry Desk

Maksim Silnikau, creator of the Ransom Cartel ransomware operation, received a 16-year prison sentence for orchestrating attacks against at least 18 companies worldwide.

11H AGOSecurity Desk

Atlassian's Rovo AI assistant can exfiltrate sensitive data despite organizational security controls. The vulnerability allows the tool to extract and transmit protected information beyond intended boundaries.

13H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.