Back redis.io Security Advisory Cve202623479 Cve202625243 Cve 2026 25588 Cve202625589 Cve 2026 23631
As part of an ongoing effort by the Redis community and Redis to maintain safety, security, and compliance posture, five security vulnerabilities in Redis have been proactively identified and [ remediated in the versions indicated below ].
If you’re a Redis Cloud customer, your Redis instance is protected against these vulnerabilities, as we’ve already upgraded our Redis Cloud service with the fixes. If you’re self-managing Redis Software, Open Source (OSS), or Community (CE) versions, there are several steps you should take to protect your Redis from exploitation.Exposure to these vulnerabilities requires an attacker to gain authenticated access to your Redis instance, making this a post-authentication issue that can lead to remote code execution (RCE).
To remediate against these vulnerabilities, upgrade your Redis to the latest versions, see our table below for full details. To minimize the risk of exploitation, it’s important to follow these best practices:
For more details on how to securely configure, deploy, and use Redis, visit the Community Edition and Enterprise Software documentation sites.
Am I impacted and how can I remediate?
If you’re a Redis Cloud customer, we’ve already upgraded our Redis Cloud service with the fixes, so no additional action is required from you.
If you’re self-managing Redis, whether Software or Community versions, upgrade your Redis to the latest release.
The versions of Redis OSS, CE and Software listed below and future versions include the corrections. Once the upgrades are performed, the vulnerability will be remediated in your environment.
You can download the latest versions here:
How can I tell if I was already exposed and how can I identify exploitation?
Refer to the table above to identify if you are on a vulnerable version.
As of this publication we have no evidence of exploitation of these vulnerabilities at Redis or in customer environments.
This isn’t a comprehensive guide, but it is a general recommendation you can adapt to your needs and operating environment.
There are a number of technical and behavioral indicators or artifacts that may be created if exploitation of the vulnerability occurred. If you for these within your Redis environment, you should be able to detect potential exploitation related to your Redis instance.
We thank the following researchers for their vigilance in reporting these vulnerabilities through our published process . We would also like to thank Wiz for the partnership and hosting Wiz ZeroDay.Cloud , where a number of these vulnerabilities were identified:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
