Affected Systems

vBulletin 5.x branch (all versions up to 5.7.5) and 6.x branch (versions up to 6.2.1). Patched in version 6.2.2 and backported to 6.2.1, 6.2.0, and 6.1.6 as Patch Level 1. No patches planned for 5.x branch.

Exploitation Status

Public proof-of-concept exploit available targeting ajax/render/pagenav endpoint. Historical pattern shows vBulletin PoCs lead to active exploitation within weeks. No confirmed active exploitation reported yet, but scanning activity expected.

Business Impact

Unauthenticated remote code execution allows complete server compromise on internet-facing vBulletin forums. Attackers can execute arbitrary PHP and system commands without credentials. Organizations running vBulletin 5.x branch face end-of-support risk with no security patches available. Gaming sites, support portals, automotive and tech forums are primary targets.

Urgency

🔴 Immediate

Recommended Actions

  • Immediately upgrade vBulletin 6.x installations to version 6.2.2 or apply Patch Level 1 to versions 6.2.1, 6.2.0, or 6.1.6
  • Migrate all vBulletin 5.x installations (5.7.5 and earlier) to supported 6.x branch as no patches will be released for 5.x
  • Block external access to /ajax/render/* endpoints at WAF or reverse proxy until patching is complete
  • Monitor web server logs for POST requests to ajax/render/pagenav or similar template endpoints with suspicious payloads
  • Conduct incident response review on unpatched vBulletin servers for indicators of compromise, focusing on unexpected PHP file creation or modified templates