vBulletin quietly fixed a site-takeover bug a month ago. the exploit just went public

A researcher found a way to turn a page number into a working PHP shell — no login required. vBulletin patched it in July. A lot of self-hosted…

Aliteq
Priya Nair · Software & Systems Editor

The short version

CVE-2026-61511 is a pre-auth remote code execution flaw in vBulletin 5.x (up to 5.7.5) and 6.x (up to 6.2.1), rated 9.8 out of 10 on CVSS 3.1.

The short version

It was reported to vBulletin on June 25, 2026, and fixed in version 6.2.2 on July 1 — plus Patch Level 1 backports for 6.2.1, 6.2.0 and 6.1.6.

The short version

Researcher Egidio Romano (EgiX) published a full working exploit on July 27, dropping the barrier to attack to almost nothing.

The short version

The 5.x branch gets no fix at all — vBulletin's guidance is to upgrade to 6.2.2, not wait for a backport.

The short version

No confirmed in-the-wild attacks yet, but a public PoC without confirmed attacks is exactly the window where mass scanning starts.

My honest take

I don't think the CVSS score is the number that matters here. It's 9.8, sure, but the number that actually matters is how many vBulletin admins have logged into their Admin CP in the last six…

Aliteq

Read the full story

vBulletin quietly fixed a site-takeover bug a month ago. the exploit just went public

Read the full story on Aliteq