View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

vBulletin patches critical pre-auth RCE flaw CVE-2026-61511 with

🚨 ACTIVE EXPLOITATION

  • vBulletin patches critical pre-auth RCE flaw CVE-2026-61511 with public exploit CVE-2026-61511
    vBulletin fixed a critical pre-auth remote code execution vulnerability in its forum software.
    • Affects vBulletin forum software versions 5.x up to 5.7.5 and 6.x up to 6.2.1
    • Vulnerability allows unauthenticated attackers to execute arbitrary PHP code via template rendering
    • Exploitation targets the ajax/render/[template] endpoint, abusing the runMaths() function's improper input sanitization
    • Public proof-of-concept exploit uses 'phpfuck' technique to bypass sanitization and execute system commands
    • Patch released in v6.2.2 and backported to 6.2.1, 6.2.0, and 6.1.6; no updates planned for 5.x branch
      πŸ“Ž Coverage: bleepingcomputer.com Β· πŸ‘ via BleepingComputer

πŸ“‹ ADVISORIES

  • Microsoft patches 'Certighost' flaw allowing AD certificate impersonation and privilege escalation
    Microsoft patched a vulnerability in Active Directory Certificate Services enabling privilege escalation.

    • Applies to Microsoft Active Directory Certificate Services (AD CS) in enterprise environments
    • Flaw allows low-privileged domain users to impersonate domain controllers via certificate enrollment
    • Exploits a broken trust boundary in certificate-based client authentication using manipulated request attributes
    • Attack uses LDAP and LSA services on attacker-controlled hosts to supply forged identity data
    • Proof-of-concept exploit released; vulnerability tracked as CVE-2026-54121 and patched in July 2026 updates
      πŸ“Ž Coverage: darkreading.com Β· πŸ“„ Original: darkreading.com Β· πŸ‘ via Dark Reading
  • Critical RCE Flaw in JetBrains TeamCity Pre-2026.1.3 Allows Unauthenticated OS Command Execution CVE-2026-63077
    JetBrains TeamCity has a critical unauthenticated remote code execution vulnerability.

    • Applies to all TeamCity On-Premises versions before 2025.11.7 and 2026.1.3
    • Vulnerability CVE-2026-63077 allows attackers to bypass authentication and execute OS commands
    • Exploited via TeamCity agent polling protocol over HTTP/HTTPS without authentication
    • Attackers can access project data, server configs, credentials, modify build jobs, and compromise CI/CD pipelines
    • Patch available in TeamCity 2025.11.7 and 2026.1.3; security patch plugin supports versions 2017.1 and later
      πŸ“Ž Coverage: cybersecuritynews.com Β· πŸ“„ Original: cybersecuritynews.com Β· πŸ‘ via Cyber Security News
  • Nginx CVE-2026-42533 Buffer Overflow Lets Attackers Execute Code via TLS Requests CVE-2026-42533
    A heap buffer overflow in Nginx allows unauthenticated attackers to execute arbitrary code.

    • Affects NGINX Plus and Open Source versions using regex-based map directives or non-cacheable variables
    • Vulnerability triggered via crafted HTTP or TLS requests exploiting Stream module's ssl_preread feature
    • Heap buffer overflow arises from incorrect length calculation in internal script engine's complex value evaluation
    • Attackers can cause worker process crashes or achieve remote code execution by bypassing ASLR
    • Discovered by Zhenpeng (Leo) Lin and Depth First Labs; F5 published advisory July 15, 2026
      πŸ“Ž Coverage: cybersecuritynews.com Β· πŸ“„ Original: cybersecuritynews.com Β· πŸ‘ via Cyber Security News

⚠️ RESEARCH & DEEP DIVES

  • Anthropic's Claude Mythos AI Finds New Cryptographic Weaknesses in HAWK and AES
    Anthropic's Claude Mythos AI discovered novel cryptographic weaknesses in HAWK and reduced-round AES.

    • Applies to HAWK, a NIST post-quantum digital signature candidate, and reduced-round AES-128 cipher
    • AI found an improved key-recovery attack halving HAWK-256's key strength by exploiting lattice symmetry
    • Discovered a MΓΆbius Bridge fingerprinting technique speeding up cryptanalysis of 7-round AES-128 by 200-800x
    • Findings do not threaten full AES-128 or deployed systems and were coordinated with NIST and HAWK authors
    • Research involved semi-autonomous AI operation costing about $100,000 and extensive human validation
      πŸ“Ž Coverage: cybersecuritynews.com Β· πŸ‘ via Cyber Security News
  • Flying Eagle Android RAT Source Code Leaked, 170 Servers Found in Hong Kong
    Researchers uncovered leaked Flying Eagle Android RAT source code and identified 170 active servers.

    • Targets Android devices via a fake Chinese Public Security Bureau app and phishing overlays
    • Leaked source code includes APK builder with evasion features like randomized class names and encrypted C2 URLs
    • 170 active servers identified across Hong Kong ASNs using TLS certificate pivots and panel fingerprints
    • Distributed and modified via Telegram channels SQLRCE0 and Yxη§‘ζŠ€ with international targeting potential
    • A successor platform called Night Dragon is under development as of June 2026
      πŸ“Ž Coverage: hunt.io Β· πŸ‘ via r/netsec
  • Anthropic AI Model Identifies Flaws in Strong Encryption Algorithms
    Anthropic's AI model discovered vulnerabilities in robust encryption algorithms.

    • Applies to widely used tough-to-crack encryption algorithms
    • Anthropic AI model analyzed and found cryptographic weaknesses
    • No CVE identifiers assigned yet
    • Details on specific algorithms or attack methods not disclosed
      πŸ“Ž Coverage: infosec.exchange Β· πŸ‘ via @metacurity@infosec.exchange

πŸ”“ CVEs & KEV

  • Other: 21 CVEs (worst 8.6)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check