← Back to feeds | Cards view

Category: Alerts

Category slug: alerts
RSS endpoint: https://tools.tornevall.net/api/rss/feed/alerts

Ungepatchter <b>vBulletin</b>-Fehler: Öffentliche PoC zeigt Pre-Auth Remote Code Execution

Permalink
Feed: Google Alert - vbulletin
Published: 2026-07-31 01:18:41
Discovered: 2026-07-31 02:46:52
Hash: 163a6fbe4e930d6b2354c26f404bdd835e500294
https://www.it-boltwise.de/ungepatchter-vbulletin-fehler-oeffentliche-poc-zeigt-pre-auth-remote-code-execution.html
Description

Ungepatchter vBulletin-Fehler: Öffentliche PoC zeigt Pre-Auth Remote Code Execution

Content

Ein öffentlicher Exploit zeigt, wie vBulletin vor der Anmeldung Code via Template-Engine bis zu eval() ausführen kann. Patch ist laut Hersteller ...

<b>vBulletin</b>: Öffentlicher Exploit zeigt Pre-Auth RCE über Template-eval() - it boltwise

Permalink
Feed: Google Alert - vbulletin
Published: 2026-07-31 00:23:07
Discovered: 2026-07-31 02:46:52
Hash: 78647c356672b27ce2c2c8589888928a84ff9ae2
https://www.it-boltwise.de/vbulletin-oeffentlicher-exploit-zeigt-pre-auth-rce-ueber-template-eval.html
Description

vBulletin: Öffentlicher Exploit zeigt Pre-Auth RCE über Template-eval() - it boltwise

Content

... vBulletin konkret: Ungeprüfte Template-Eingaben können bis in PHPs eval()-Funktion führen. Betroffen sind laut SSD Secure Disclosure vBulletin 6.2 ...

討論區軟體<b>vBulletin</b>重大漏洞PoC公開,未登入也能在伺服器執行程式碼 - iThome

Permalink
Feed: Google Alert - vbulletin
Published: 2026-07-30 08:51:28
Discovered: 2026-07-30 10:24:36
Hash: 269052dc19084ae741a1ac697e1867d3572fb7ec
https://www.ithome.com.tw/news/177717
Description

討論區軟體vBulletin重大漏洞PoC公開,未登入也能在伺服器執行程式碼 - iThome

Content

討論區軟體vBulletin範本系統的輸入過濾可遭繞過,未登入的攻擊者能從公開頁面觸發任意PHP程式碼,目前概念驗證已公開,5系列及6.2.1以前版本管理員應儘速升級 ...

<b>vBulletin</b> forum software vulnerable to remote code execution | brief - SC Media

Permalink
Feed: Google Alert - vbulletin
Published: 2026-07-30 08:25:35
Discovered: 2026-07-30 10:24:36
Hash: 61783d310f1d9e8e17d38409e5b61fd22a54d447
https://www.scworld.com/brief/vbulletin-forum-software-vulnerable-to-remote-code-execution
Description

vBulletin forum software vulnerable to remote code execution | brief - SC Media

Content

A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering ...

Kritiek lek in forumsoftware <b>vBulletin</b> maakt remote code execution mogelijk - Security.NL

Permalink
Feed: Google Alert - vbulletin
Published: 2026-07-29 21:40:45
Discovered: 2026-07-30 10:24:36
Hash: e061ef342362d96f9bedcad67c9e1ba82f1195dd
https://www.security.nl/posting/947073/Kritiek+lek+in+forumsoftware+vBulletin+maakt+remote+code+execution+mogelijk
Description

Kritiek lek in forumsoftware vBulletin maakt remote code execution mogelijk - Security.NL

Content

Tienduizenden fora op internet draaien op vBulletin. De kwetsbaarheid bevindt zich in een PHP-script van vBulletin dat een remote aanvaller kan ...

<b>vBulletin</b> Kritik Açığı Kimlik Doğrulama Olmadan Sunucu Ele Geçirilmesine Yol Açıyor

Permalink
Feed: Google Alert - vbulletin
Published: 2026-07-29 18:09:39
Discovered: 2026-07-30 10:24:37
Hash: 7302a93afd502777507f7499bba84cf17d50db96
https://www.cozumpark.com/vbulletin-kritik-acigi-kimlik-dogrulama-olmadan-sunucu-ele-gecirilmesine-yol-aciyor/
Description

vBulletin Kritik Açığı Kimlik Doğrulama Olmadan Sunucu Ele Geçirilmesine Yol Açıyor

Content

vBulletin, kritik güvenlik açığını gideren güncellemeyi yayınladı. vBulletin kritik açığı, kimlik doğrulama olmadan uzaktan kod çalıştırılmasına ...

Hackers target US firms in FastJson RCE zero-day attacks - Bleeping Computer

Permalink
Feed: Google Alert - vbulletin
Published: 2026-07-28 23:53:26
Discovered: 2026-07-29 01:48:31
Hash: d882e3b23a64a7f516a4bde5262bb64acaba8789
https://www.bleepingcomputer.com/news/security/hackers-target-us-firms-in-fastjson-rce-zero-day-attacks/
Description

Hackers target US firms in FastJson RCE zero-day attacks - Bleeping Computer

Content

Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction ...

Public Exploit Lands for <b>vBulletin's</b> Pre-Auth RCE, CVE-2026-61511 - Latest Hacking News

Permalink
Feed: Google Alert - vbulletin
Published: 2026-07-28 20:19:43
Discovered: 2026-07-29 01:48:31
Hash: 3baa45ebe2d241311f5fb7d466dc06ace4f451ed
https://latesthackingnews.com/2026/07/28/vbulletin-rce-vulnerability-cve-2026-61511/amp/
Description

Public Exploit Lands for vBulletin's Pre-Auth RCE, CVE-2026-61511 - Latest Hacking News

Content

... vBulletin landed on July 27, exposing forum administrators who skipped last month's patch cycle. The vBulletin RCE vulnerability, tracked as CVE ...

<b>vBulletin</b> fixes critical pre-auth RCE flaw with public exploit - Bleeping Computer

Permalink
Feed: Google Alert - vbulletin
Published: 2026-07-28 20:12:50
Discovered: 2026-07-29 01:48:31
Hash: 5076507fb5f5720f57398d2bd2baaae759a05856
https://www.bleepingcomputer.com/news/security/vbulletin-fixes-critical-pre-auth-rce-flaw-with-public-exploit/
Description

vBulletin fixes critical pre-auth RCE flaw with public exploit - Bleeping Computer

Content

A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template ...

WARNING - Public PoC released for a <b>vBulletin</b> flaw that turns one unauthenticated request ...

Permalink
Feed: Google Alert - vbulletin
Published: 2026-07-28 08:02:52
Discovered: 2026-07-28 09:17:25
Hash: ec3662b4a817951307614e9b9982b8e65d63e637
https://x.com/TheHackersNews/status/2081753483259335139
Description

WARNING - Public PoC released for a vBulletin flaw that turns one unauthenticated request ...

Content

The Hacker News (@TheHackersNews). 147 likes 3 replies. WARNING - Public PoC released for a vBulletin flaw that turns one unauthenticated ...