CRITICAL
vBulletin Fixes Critical Pre-Auth RCE Flaw With Public Exploit
vBulletin has patched a critical vulnerability that lets unauthenticated attackers execute arbitrary PHP code through the forum software’s template rendering engine. A public exploit for the flaw is already circulating, raising the urgency for admins running affected versions. Site operators should apply the vendor patch immediately and check internet-facing installations for signs of compromise.