megachangelog
Security2026-08-11

WAF Protection for vBulletin RCE and Detection Improvements

Cloudflare WAF now protects against vBulletin CVE-2026-61511 remote code execution vulnerability with a new detection rule. Two existing detections for version control information disclosure and vBulletin code injection have been improved and merged into their base rules for stronger coverage.

This release introduces new protection for a remote code execution vulnerability in vBulletin and improves two existing detections.

Key Findings

  • A new detection provides protection against vBulletin CVE-2026-61511.
  • Two existing detections have been improved to strengthen coverage.

Impact

Successful exploitation of CVE-2026-61511 may lead to remote code execution on affected vBulletin systems, potentially resulting in unauthorized access, data exposure, service disruption, and broader compromise of the hosting environment. Administrators are strongly encouraged to apply vendor updates and recommended mitigations.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed Ruleset...94f3006bN/AvBulletin - Remote Code Execution - CVE:CVE-2026-61511LogBlockThis is a new detection.
Cloudflare Managed Ruleset...098b749eN/AVersion Control - Information Disclosure - BetaLogBlockThis rule is merged into the original rule "Version Control - Information Disclosure" (ID: ...0550c529)
Cloudflare Managed Ruleset...d56225d8N/AvBulletin - Code Injection - Invalid image format - CVE:CVE-2019-17132 - BetaLogBlockThis rule is merged into the original rule "vBulletin - Code Injection - Invalid image format - CVE:CVE-2019-17132" (ID: ...8fe9f1c7)
wafsecuritycvevulnerabilityvbulletin

Source: original entry ↗