releases.sh

vBulletin RCE CVE blocked; two detections upgraded to Block

1 feature2 enhancements3 fixesThis release1 featureNew capabilities2 enhancementsImprovements to existing features3 fixesBug fixesAI-tallied from the release notes
From the original release noteView original ↗

This release introduces new protection for a remote code execution vulnerability in vBulletin and improves two existing detections.

Key Findings

  • A new detection provides protection against vBulletin CVE-2026-61511.
  • Two existing detections have been improved to strengthen coverage.

Impact

Successful exploitation of CVE-2026-61511 may lead to remote code execution on affected vBulletin systems, potentially resulting in unauthorized access, data exposure, service disruption, and broader compromise of the hosting environment. Administrators are strongly encouraged to apply vendor updates and recommended mitigations.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...94f3006b

N/A

vBulletin - Remote Code Execution - CVE:CVE-2026-61511

Log

Block

This is a new detection.

Cloudflare Managed Ruleset

...098b749e

N/A

Version Control - Information Disclosure - Beta

Log

Block

This rule is merged into the original rule "Version Control - Information Disclosure" (ID: ...0550c529)

Cloudflare Managed Ruleset

...d56225d8

N/A

vBulletin - Code Injection - Invalid image format - CVE:CVE-2019-17132 - Beta

Log

Block

This rule is merged into the original rule "vBulletin - Code Injection - Invalid image format - CVE:CVE-2019-17132" (ID: ...8fe9f1c7)

Fetched August 11, 2026