安全客•August 27, 2026•🇨🇳Translated from Chinese

Redis Patch Bypass Enables Multiple RCE Exploits as PoCs for TLS and Stream Vulnerabilities Go Public

Redis has suffered a rapid series of remote code execution vulnerabilities over the past month, with the latest TLS pending list flaw (QVD-2026-58458) now accompanied by public technical details and a working proof-of-concept. Security researchers have already reproduced the issue, and the vendor released an emergency fix. Because Redis is ubiquitous in backend architectures for caching, sessions, message queues, and leaderboards, any vulnerability in the service immediately affects a wide range of organizations.

The most concerning disclosure is the July patch-bypass vulnerability targeting CVE-2026-25243. The original fix addressed a reference-counting problem with shared NACK objects in stream consumer groups, yet the remediation was incomplete. Attackers can chain the commands XGROUP, EVAL, and RESTORE to trigger a Double Free memory corruption primitive, ultimately achieving arbitrary code execution on the server. Patch-bypass issues are particularly dangerous because they target teams that believe they have already mitigated the risk after applying the initial update.

The affected versions for the bypass are Redis 6.2.22 and earlier, 7.4.9 and earlier, and 8.6.4 and earlier; the official remediation begins at version 8.8.0. The August 26 disclosure of QVD-2026-58458 similarly provides a public PoC, lowering the barrier for exploitation to the level of script kiddies copying existing code. Although all three vulnerabilities require authentication, real-world deployments frequently use weak passwords, empty passwords, or publicly reachable instances, rendering the authentication requirement ineffective against automated scanners.

Once an attacker gains control, the consequences extend far beyond data leakage. Redis instances often sit at the center of internal networks; code execution allows attackers to harvest credentials, map internal assets, and pivot to databases and application servers. The following practical steps are recommended for defenders:

  • Perform a complete asset inventory covering production, test, and shadow instances, then upgrade every affected version to the latest patched release.
  • Enforce strict network controls so that Redis is never exposed to the public internet and is reachable only from explicitly allowed internal IPs; immediately remediate weak or missing passwords via requirepass or ACLs.
  • Enable logging and audit for high-risk command sequences, especially non-standard usage of XGROUP, EVAL, and RESTORE; restrict Lua script execution via ACLs when not required.
  • Update container base images in addition to host-level patches to avoid version drift between the running container and the patched host.
  • Incorporate official Redis security announcements and threat-intelligence feeds into routine monitoring processes.

This wave of vulnerabilities underscores that the security posture of foundational infrastructure components directly determines the resilience of the entire environment. With public PoCs, patch bypasses, and near-universal version coverage, the race is now between rapid remediation and automated scanning campaigns.

Related articles

Hispasec•Vulnerabilities & Exploits

LibreOffice and Apache OpenOffice Flaws Enable Remote Code Execution via Malicious Spreadsheets Without Macro Warnings

Two vulnerabilities, CVE-2026-63277 in LibreOffice Calc and CVE-2026-59265 in Apache OpenOffice, allow attackers to execute arbitrary code simply by tricking users into opening specially crafted spreadsheet files. The flaws exploit Java integration and class path handling, bypassing traditional macro security prompts entirely. LibreOffice has already released fixes in versions 26.2.5 and 26.8.0 that restrict class path entries to local file URLs only. Apache OpenOffice 4.1.16 and earlier remain vulnerable, with the stable patch expected in 4.1.17; interim mitigation requires disabling Java integration. The issues highlight risks in office suites that process untrusted documents containing external data connections or JDBC references. Organizations are advised to enforce least-privilege execution and avoid opening files from unknown sources until patches are applied.

BoletimSec•Vulnerabilities & Exploits

Web Application Vulnerabilities Surge as AI-Driven Development Outpaces Security Testing

The number of vulnerabilities in web applications continues to grow each quarter, driven in part by the rapid adoption of artificial intelligence in software development pipelines. While integrating AI tools boosts productivity and shortens release cycles, many organizations fail to match this speed with equivalent security testing and validation processes. As a result, increasing amounts of code reach production environments without ever being assessed from an attacker’s perspective. Cybercriminals have quickly recognized this gap, exploiting repeated flaw patterns in applications that skip security reviews. The article emphasizes that pentesting must become a recurring part of the development cycle, conducted weekly or monthly to match the pace of updates. Continuous security testing allows teams to identify and remediate issues before they can be weaponized. Developing rapidly with AI is not inherently risky, but releasing unvalidated code transforms speed into exposure.

BoletimSec•Vulnerabilities & Exploits

Microsoft Fixes CVE-2026-96940 in Exchange Server Allowing Authenticated Mailbox Access

Microsoft has patched CVE-2026-96940, a CVSS 8.8 vulnerability in Exchange Server that lets any authenticated user read other users' mailboxes without administrative rights. The flaw exposes full message content and attachments including contracts, spreadsheets, and sensitive documents. Affected on-premises versions include Exchange Server Subscription Edition RTM, Exchange 2016 CU23, Exchange 2019 CU15, and Exchange 2019 CU14. Exchange Online users are protected because the fix was applied server-side. Microsoft rates exploitation as likely but reports no confirmed attacks in the wild at disclosure time. The issue turns a single low-privilege credential into broad access to executive, legal, and financial correspondence.

Habr•Vulnerabilities & Exploits

New Spectre-v2 Variant Uses JIT Compiler Branch Target Reuse for Cross-Process Data Extraction

Researchers from the Netherlands and Italy have published a paper detailing a fresh Spectre-v2 attack that reuses branch predictor state instead of injecting new instructions. The technique leverages the JIT compiler cBPF inside the Linux kernel to train the branch target predictor, enabling speculative execution that leaks sensitive data such as hashed root passwords. Practical demonstrations extracted credentials from the su process in an average of three to five minutes on AMD, Intel, and ARM processors. Partial success was shown with SpiderMonkey in Firefox and GraalVM, although realistic end-to-end attacks were not achieved with those engines. The work also covers additional topics including forensic detection of attacks against 1C servers, a record Debian Linux kernel patch set, zero-day fixes in TeamViewer and Apple Core Graphics, and critical flaws in Dell Container Storage Modules.