High
CVE-2026-61511
vBulletin RCE vulnerability CVE-2026-61511 with public exploit
Vendor / product: vBulletin 5.x/6.x
Event date: 2026-07-27
Public PoC: Yes
First tracked by RiskWire: 2026-07-28
Sources & citations (4)
- vBulletin CVE-2026-61511: Unauthenticated RCE via Public AJAX Template to `eval()` dev.to · 2026-07-29
- vBulletin fixes critical pre-auth RCE flaw with public exploit bleepingcomputer.com · 2026-07-28
- vBulletin forum software vulnerable to remote code execution scworld.com · 2026-07-29
- Ankura CTIX FLASH Update – July 28, 2026 mondaq.com:443 · 2026-07-29
References
See CVE-2026-61511 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →