Researchers disclosed multiple authenticated remote code execution paths in Redis, showing how users with valid Redis credentials could potentially escalate from datastore access to host-level shell access on stock builds including Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. The reported issues include a stream consumer-group shared-NACK double-free linked to the CVE-2026-25589 incomplete-fix family and a heap overflow in the bundled RedisBloom TDigest module affecting Redis 8.8.0. The attack chains rely on commonly enabled capabilities such as EVAL, RESTORE, and XGROUP, and the report said the double-free was only fully fixed in 8.8.0 while that same release still remained exposed to the RedisBloom bug at disclosure time.
At the same time, new offensive-security tooling emerged to help identify exposed Redis deployments. A Rapid7 Metasploit pull request introduced an auxiliary scanner for CVE-2025-49844 ("RediShell") that checks whether a Redis server is running an unpatched branch and whether Lua EVAL is reachable, highlighting how configuration choices such as ACLs can reduce practical exploitability even on vulnerable versions. The combined disclosures underscore the need to patch Redis promptly, restrict dangerous commands, keep Redis off the public internet, rotate credentials, review RedisBloom usage, and monitor for anomalous command activity that could indicate exploitation attempts.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
A GitHub repository published exploit code and usage examples for authenticated Redis RCE paths affecting Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. The repository also referenced a TopK module wild-free issue affecting Redis 8.8.0 and 8.8.1, alongside exploitation primitives involving commands such as RESTORE, EVAL, XGROUP, and TopK_Destroy.
A Metasploit auxiliary scanner module, redis_lua_uaf_cve_2025_49844, was created and tested to detect Redis servers practically exposed to CVE-2025-49844 (RediShell). The module checks whether a target is on an unpatched branch and whether Lua EVAL is reachable, with examples showing vulnerable, patched, and ACL-restricted cases.
A reported research effort tied to the Kimi K3 AI agent identified multiple authenticated remote code execution paths in stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. The findings included a stream consumer-group shared-NACK double-free linked to the CVE-2026-25589 incomplete-fix family and a heap overflow in the bundled RedisBloom TDigest module affecting Redis 8.8.0.
Redis released seven branch-specific security updates on July 23, 2026 after public authenticated RCE proof-of-concepts were published for Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. The company advised users to upgrade, revoke RESTORE where unnecessary, and restrict untrusted network access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.