vBulletin Ships Emergency Patch for Critical Pre-Auth RCE — PoC Is Public, 5.x Branch Is Abandoned
CVE-2026-61511 enables unauthenticated PHP code execution through template rendering in vBulletin 5.x and 6.x. A public exploit exists, and the 5.x branch will receive no fix whatsoever.