Attackers actively exploited CVE-2020-17496, a pre-authentication remote code execution flaw in vBulletin, to run arbitrary PHP code on vulnerable forums. The bug bypassed the earlier fix for CVE-2019-16759 by abusing vBulletin’s template rendering logic, specifically the widget_tabbedcontainer_tab_panel template to indirectly invoke widget_php. Palo Alto Networks Unit 42 reported exploitation beginning shortly after disclosure, with multiple unrelated actors scanning for exposed systems and attempting remote command execution.
Observed attacks included reading sensitive files such as /etc/passwd, writing PHP web shells, and delivering additional malware. Unit 42 said intruders used the vulnerability to download a Perl-based Shellbot and a Mirai variant known as Sora, underscoring the risk of both persistent compromise and botnet recruitment. vBulletin issued a patch for affected versions, and organizations running the software were urged to update immediately because of the broad installed base and ongoing exploitation.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
Unit 42 observed the first exploitation of CVE-2020-17496 in the wild on Aug. 10, 2020. Multiple unrelated attackers used the flaw for scanning, command execution, file reading, web shell deployment, and malware delivery.
vBulletin released a patch for the pre-authentication remote code execution vulnerability CVE-2020-17496 on Aug. 10, 2020. The flaw bypassed the earlier fix for CVE-2019-16759.
A remote code execution vulnerability tracked as CVE-2019-16759 was disclosed for vBulletin in September 2019. CVE-2020-17496 was later described as a bypass of the fix for this earlier flaw.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 41 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
cve.mitre.org
Open sourceunit42.paloaltonetworks.com
Open sourcecve.mitre.org
Open sourceblog.exploitee.rs
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.