Critical vBulletin Flaws Exploited in the Wild

Red | Vulnerability Report

Critical vulnerabilities, CVE-2025-48827 and CVE-2025-48828, have highlighted the serious risks of operating a public-facing vBulletin forum. These flaws, which are actively being exploited in the wild, enable attackers to gain full control of servers without authentication. To protect against such threats, site operators should urgently apply updates, limit access to administrative interfaces, and enforce robust security controls to minimize the risk of exploitation.

Reduce real exposure. Not just vulnerability volume.