Public Exploit Turns vBulletin Into a Server Foothold

A public exploit turns this from a patchable flaw into an immediate takeover risk. A normal forum request can now be used to push attacker-controlled text into template rendering, where vBulletin treats it as code and executes PHP before anyone logs in. The issue is CVE-2026-61511 in vBulletin's template engine. It affects vBulletin 5.x through 5.7.5 and 6.x through 6.2.1, and the vendor has already shipped 6.2.2 as the fix. The standard forum threat model does not hold here. An exposed, unpatched vBulletin host can become a beachhead into the rest of the server and any adjacent web assets that sit behind it.

Part of the PlainSec briefing for 2026-07-29

Sources