Skip to main content
QUIETLYTIC
Vulnerability

vBulletin Vulnerability (CVE-2026-61511)

CVE-2026-61511 is a CVSS 9.8 eval injection flaw in vBulletin allowing unauthenticated RCE, reported exploited by VulnCheck with a near-maximum EPSS score.

CVE-2026-61511
Threat Level
CRITICAL
CVSS
9.8
Status
Active Exploitation
Confidence
Medium
Affected Products
vBulletin, vBulletin 5.x (through 5.7.5) and 6.x (through 6.2.1)

CVE-2026-61511 carries a CVSS 3.1 base score of 9.8 against vBulletin, a widely deployed commercial forum software platform. NVD classifies it as CWE-95 (Improper Neutralization of Directives in Dynamically Evaluated Code, commonly called “Eval Injection”) and states the affected range as 5.x through version 5.7.5 and 6.x through version 6.2.1. VulnCheck’s KEV feed reports the CVE as exploited, dated August 27, 2026.

That exploitation report is single-sourced. CISA has not added CVE-2026-61511 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion on September 19, 2026. VulnCheck’s catalog admits vendor and researcher exploitation reporting on broader criteria than CISA’s own listing process has accepted; no Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.

What the flaw is

NVD’s description names the vulnerable method directly: vB5_Template_Runtime::runMaths(), part of vBulletin’s template runtime, evaluates mathematical expressions from template input. NVD states the flaw is reachable through the pagenav[pagenumber] parameter via the unauthenticated ajax/render template route, and that the regex filter meant to restrict what characters can appear in that input is insufficiently restrictive — permitting an encoding technique built entirely from characters the filter allows through, which NVD’s description names but which we are not detailing further here, to reconstruct and execute arbitrary PHP code. No authentication is required, consistent with the CVSS vector’s PR:N (no privileges required) and UI:N (no user interaction) values.

We are reporting the existence and classification of this technique, not its construction — NVD’s description names the encoding category but the specific construction needed to weaponize it is exactly the kind of technical reproduction detail this publication does not carry, regardless of what a source document contains.

Evidence and confidence

  • Medium confidence — the CVSS 9.8 score, the vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), the CWE-95 classification, and the specific vulnerable method and parameter (vB5_Template_Runtime::runMaths(), pagenav[pagenumber]) all trace to NVD alone. The exploitation report traces to VulnCheck KEV alone.
  • Very high exploitation probability — FIRST’s EPSS model scores this CVE at 0.70766, a 99.365th percentile score as of our ingestion — one of the highest EPSS scores in our recent KEV coverage, placing it among the small fraction of all scored CVEs the model considers most likely to see continued exploitation.

No field is in conflict between our two sources. NVD’s reference list includes vBulletin’s own forum announcements of security patches for versions 6.2.1, 6.2.0, and 6.1.6, plus a separate announcement that version 6.2.2 is available — indicating the 6.x branch has a vendor-issued fix, though NVD’s description does not state a specific remediated version number for the 5.x branch covered by this CVE.

Why this matters

vBulletin is long-established, widely deployed forum software, which means the population of installations running an affected 5.x or 6.x version is likely to include sites that have been running the same platform for years without close security maintenance — exactly the profile that tends to be slow to patch even a critical, unauthenticated, no-privileges-required remote code execution flaw. The 99.365th-percentile EPSS score independently corroborates what the technical facts already suggest: this is one of the more urgent VulnCheck-only advisories we have covered, on the strength of the vulnerability’s own characteristics rather than the single-source exploitation report alone.

Given NVD’s reference list points to vBulletin’s own 6.2.2 announcement, operators on the 6.x branch have a clear upgrade target. Operators on the 5.x branch should check directly with vBulletin’s own security announcements, since NVD’s record does not name a specific 5.x remediated version.

Frequently Asked Questions

What is CVE-2026-61511? A CVSS 9.8 eval injection vulnerability (CWE-95) in vBulletin’s template runtime, affecting 5.x through 5.7.5 and 6.x through 6.2.1, allowing unauthenticated remote attackers to execute arbitrary PHP code via the pagenav[pagenumber] parameter.

Is CVE-2026-61511 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated August 27, 2026. That report is single-sourced; CISA has not listed this CVE as of our September 19, 2026 ingestion, and we have no independent corroboration. FIRST’s EPSS model independently scores this CVE at the 99.365th percentile, corroborating high exploitation likelihood through a different signal.

Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.

Which version fixes this? NVD’s references point to vBulletin’s own announcements of patches for 6.2.1, 6.2.0, and 6.1.6, and a further 6.2.2 release. NVD’s description does not name a specific fixed version for the 5.x branch; check vBulletin’s own security announcements directly.

Do I need to be logged in for my forum to be at risk? No. NVD states the flaw is reachable through the unauthenticated ajax/render template route.


Severity, vector, weakness classification, vulnerable method, and affected-version range sourced from the National Vulnerability Database record for CVE-2026-61511, which references vBulletin’s own security patch announcement and 6.2.2 release announcement. Exploitation status and the August 27, 2026 catalog date are reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our ingestion through September 19, 2026. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools