Critical vBulletin Flaw Lets Unauthenticated Attackers Execute PHP Code Remotely
vBulletin has patched CVE-2026-61511, a critical remote code execution flaw that could let unauthenticated attackers execute arbitrary PHP code and compromise vulnerable forum servers. This issue affects vBulletin versions 6.2.1 and earlier as well as versions 6.1.6 and earlier. The flaw exists in the file /includes/vb5/template/runtime.php, specifically within the vB5_Template_Runtime::runMaths() method. This function processes values […]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
