CVE-2026-23479
CVSS 8.8 HIGH: redis is an in-memory data structure store. EPSS 2% (73º percentile).
Vulnerabilità ed exploit
Un login gate non aiuta molto quando l’utente Redis predefinito ha già i privilegi di cui l’exploit ha bisogno. Nelle distribuzioni cloud che lasciano Redis sull’account predefinito o senza password, un use-after-free autenticato diventa un rischio pratico su scala Internet invece di un bug circoscritto.
1 fonte · 4 giu
CVSS 8.8 HIGH: redis is an in-memory data structure store. EPSS 2% (73º percentile).
The Hacker News
Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)
Redis CVE-2026-23479 enables authenticated RCE; affecting versions since 7.2.0, patched May 5 to reduce exploitation risk.
originalePart of the PlainSec briefing for 2026-06-03
Every edition of this story: Redis senza password trasforma il bug autenticato in un’esposizione