Redis disclosed five vulnerabilities affecting Redis Cloud, Redis Software, and Redis OSS/CE that could allow authenticated attackers to achieve remote code execution, system compromise, data exfiltration, or service disruption. The issues tracked as CVE-2026-23479, CVE-2026-25243, CVE-2026-25588, CVE-2026-25589, and CVE-2026-23631 include an invalid memory access flaw in the RESTORE command, a use-after-free bug in the unblock client flow, and a Lua use-after-free condition in certain replica configurations. Public advisories and downstream alerts described four of the bugs as high severity and one as medium severity, with multiple flaws capable of leading to arbitrary code execution.
Redis said Redis Cloud deployments had already been patched and required no customer action, while self-managed users were told to upgrade to fixed releases across Redis OSS/CE, Redis Software, RedisTimeSeries, and RedisBloom. Government and national CERT notices echoed the vendor guidance and urged administrators to review the advisories and apply updates promptly. Redis also said it had no evidence of active exploitation at publication time, but recommended immediate patching and hardening measures such as restricting network exposure, enforcing strong authentication, keeping protected mode enabled where appropriate, and applying least-privilege access controls.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-06, dCERT issued advisory 2026-1346 warning that multiple Redis vulnerabilities could allow execution of arbitrary code. The notice amplified the vendor disclosure for defenders and administrators.
On 2026-05-05, the Canadian Centre for Cyber Security published alert AV26-423 highlighting Redis's advisory and urging administrators to review the vendor guidance and apply necessary updates. The alert framed the issue as a vendor-driven vulnerability notification rather than evidence of an active intrusion campaign.
In its May 5, 2026 disclosure, Redis said it had no evidence that the vulnerabilities were being actively exploited in the wild at the time of publication. The company nevertheless urged immediate patching and deployment hardening measures such as network restrictions, strong authentication, protected mode, and least-privilege access.
As part of the 2026-05-05 advisory, Redis directed self-managed users to upgrade to fixed versions across Redis OSS/CE, Redis Software, RedisTimeSeries, and RedisBloom. Redis also stated that Redis Cloud deployments had already been patched and required no customer action.
On 2026-05-05, Redis published GitHub security advisories detailing specific vulnerability classes, including invalid memory access in the RESTORE command, a use-after-free in the unblock client flow, and a Lua use-after-free issue. These advisories provided the technical characterization of multiple flaws that could lead to remote code execution.
On 2026-05-05, Redis published a security advisory covering five vulnerabilities affecting Redis Software and Redis OSS/CE: CVE-2026-23479, CVE-2026-25243, CVE-2026-25588, CVE-2026-25589, and CVE-2026-23631. The flaws were described as enabling impacts including remote code execution, system compromise, data exfiltration, or service disruption under certain conditions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcedcert.de
Open sourcecyber.gc.ca
Open sourcegithub.com
Open sourceredis.io
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.