Redis disclosed and fixed five vulnerabilities in Redis OSS/CE, including four high-severity issues and one medium-severity flaw, warning that several bugs could lead to remote code execution after authentication. The most serious issue, CVE-2026-23479, is a use-after-free in blocking-client code that can enable arbitrary OS command execution on the host running Redis; Redis said it affects versions beginning with 7.2.0 across multiple stable branches. The broader set of flaws also includes invalid memory access bugs in the RESTORE command, including module-specific cases involving RedisTimeSeries and RedisBloom, as well as a Lua use-after-free affecting certain replica configurations.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
A public technical write-up became available describing CVE-2026-23479, which Team Xint Code, an autonomous AI bug-hunting tool, discovered in Redis blocking-client code.
CVE-2026-23479 was introduced by the interaction of two Redis commits made in 2023, creating an authenticated use-after-free vulnerability in blocking-client code.
Redis publicly disclosed and remediated five vulnerabilities affecting Redis OSS/CE, including four high-severity issues and one medium-severity flaw that could potentially lead to remote code execution after authentication. Redis said it had no evidence of exploitation at the time of disclosure and provided mitigation and detection guidance.
A public report described a multi-stage exploitation chain for CVE-2026-23479 requiring authenticated Redis access, including a heap address leak, triggering a use-after-free via client eviction and unblocked client handling, and reclaiming freed memory with a fake client structure. The write-up said attackers could abuse a writable .got.plt entry under partial RELRO to redirect strcasecmp to system, enabling Redis commands to execute in the host shell.
On 2026-05-05, Redis released patched versions addressing CVE-2026-23479 and other disclosed vulnerabilities, including Redis OSS/CE 6.2.22, 7.2.14, 7.4.9, 8.2.6, 8.4.3, and 8.6.3, with additional module updates for RedisTimeSeries and RedisBloom.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcethehackernews.com
Open sourceseclists.org
Open sourcecvereports.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.