
Critical vBulletin Pre-Auth RCE Flaw Enables Arbitrary PHP Code Execution
A critical vulnerability in vBulletin lets unauthenticated remote attackers execute arbitrary PHP code on a vulnerable forum server, creating a direct path to server compromise. Tracked as CVE-2026-61511, the issue affects vBulletin 6.2.1 and earlier, as well as version 6.1.6 and earlier. The flaw was disclosed on July 27, 2026, by a researcher working with […]
The post Critical vBulletin Pre-Auth RCE Flaw Enables Arbitrary PHP Code Execution appeared first on Cyber Security News.