vBulletin disclosed and patched CVE-2026-61511, a critical unauthenticated remote code execution flaw in its template engine that can let attackers execute arbitrary PHP code on self-hosted forum servers. The bug affects multiple releases, including 5.x through 5.7.5 and 6.x through 6.2.1 according to advisory coverage, and is fixed in 6.2.2 with patches also issued for supported branches. The vulnerability is rooted in vB5_Template_Runtime::runMaths() in vb5/template/runtime.php, where insufficient input filtering allows attacker-controlled expressions to reach PHP's eval().

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
In late June 2026, vBulletin issued patches for versions 6.2.1, 6.2.0, and 6.1.6 to address the pre-authentication remote code execution flaw later tracked as CVE-2026-61511.
On July 27, 2026, public exploit details were released for the patched vBulletin flaw, showing how attacker-controlled input through the ajax/render pagenav route could reach eval() via vB5_Template_Runtime::runMaths(). Reports noted the published proof of concept had a minor typo, but the underlying exploit path was valid when corrected.
On July 1, 2026, vBulletin released version 6.2.2 containing a fix for CVE-2026-61511, an eval injection flaw in the template runtime that can enable unauthenticated remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcegithub.com
Open sourcebleepingcomputer.com
Open sourcecryptika.com
Open sourcessd-disclosure.com
Open sourcecvefeed.io
Open sourcereddit.com
Open sourceforum.vbulletin.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.