JFrog Security published a full exploit chain for a high-severity Redis stack buffer overflow, CVE-2025-62507 (CVSS 8.8), affecting Redis 8.2.0–8.2.2. The flaw is in the new XACKDEL command, where Redis fails to bounds-check the number of message IDs copied into a fixed-size stack array, enabling attacker-controlled overwrite of stack memory and potential control of the return address. The research also highlighted that the official Redis Docker image was compiled without stack canary protections, materially lowering exploitation difficulty and enabling practical remote code execution (RCE) via return-oriented techniques.
Separately, a critical remote command-injection issue was reported in Apache bRPC’s built-in heap profiler service, CVE-2025-60021, affecting all versions prior to 1.15.0. The /pprof/heap endpoint fails to sanitize the extra_options parameter before it is incorporated into command execution for jemalloc profiling, allowing unauthenticated attackers to execute arbitrary system commands with the bRPC process’s privileges when the endpoint is exposed to untrusted networks. Recommended remediation is to upgrade to Apache bRPC 1.15.0+ or otherwise disable/restrict access to the vulnerable profiling endpoint in affected deployments.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Redis resolved the XACKDEL stack overflow vulnerability in version 8.3.2. The issue had exposed vulnerable internet-facing deployments, with cited Shodan data indicating nearly 3,000 exposed servers running affected versions.
JFrog Security Research disclosed a full exploit chain for Redis vulnerability CVE-2025-62507, a stack buffer overflow in the XACKDEL command affecting Redis 8.2.0 through 8.2.2. The researchers showed reliable remote code execution in official Redis Docker containers by leveraging the lack of stack canary protections and building a ROP-based reverse shell exploit.
A critical vulnerability, CVE-2025-60021, was disclosed in Apache bRPC's /pprof/heap endpoint, where the extra_options parameter can be abused to execute arbitrary system commands without authentication. Successful exploitation can lead to remote code execution, lateral movement, data theft, service disruption, and persistence.
Apache bRPC addressed a critical command-injection flaw in its built-in heap profiler service in version 1.15.0, with upstream patch PR #3101 also available as a mitigation. The vulnerability affects all earlier versions when the jemalloc profiling endpoint is exposed to untrusted networks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.