CVE-2026-23479
CVSS 8.8 HIGH: redis is an in-memory data structure store. EPSS 2% (73º percentile).
Vulnerabilità · 118 giorni fa
Un login gate non aiuta molto quando l’utente Redis predefinito ha già i privilegi di cui l’exploit ha bisogno. Nelle distribuzioni cloud che lasciano Redis sull’account predefinito o senza password, un use-after-free autenticato diventa un rischio pratico su scala Internet invece di un bug circoscritto.
CVSS 8.8 HIGH: redis is an in-memory data structure store. EPSS 2% (73º percentile).
1 fonte che coprono questa storia
Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)
Redis CVE-2026-23479 enables authenticated RCE; affecting versions since 7.2.0, patched May 5 to reduce exploitation risk.
Part of the PlainSec briefing for 2026-06-03