Researchers detailed how attackers can abuse improperly exposed "protected" method handling in vBulletin to achieve unauthenticated remote code execution on internet-facing forums. The issue affects vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 running on PHP 8.1 or newer, and is tracked as CVE-2025-48827 and CVE-2025-48828. Technical analysis showed the flaws can be chained from remote access to protected method invocation and full code execution on vulnerable servers.
CSIRT.SK reported the vulnerabilities are being actively exploited in the wild, with abuse observed since at least May 2025, while many exposed instances remain unpatched. The vendor had reportedly released fixes in April 2024 without detailed public disclosure, leaving administrators unaware of the severity until later reporting. Defenders are being urged to update affected installations to the recommended patched versions or the latest release and to review server and application logs for evidence of compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK published an alert describing CVE-2025-48827 and CVE-2025-48828 as critical, actively exploited vulnerabilities in vBulletin. The advisory urged administrators to update to fixed versions and review logs for signs of compromise.
CSIRT.SK reported that the critical vBulletin vulnerabilities CVE-2025-48827 and CVE-2025-48828 have been actively exploited since at least May 2025. The bugs allow unauthenticated remote exploitation on vulnerable installations running PHP 8.1 or newer, including remote code execution.
The vendor reportedly released updates in April 2024 that addressed what were later identified as CVE-2025-48827 and CVE-2025-48828, but did so without detailed public disclosure. The flaws affected vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3.
A technical write-up dissecting an N-day remote code execution issue in vBulletin was published, focusing on abuse of a supposedly protected method. The analysis documented the vulnerability mechanics and exploitation path.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.