CVE-2026-23479Disclosure(redis / redis)

CRITICALCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 21 mentions and remains active

Immediate actions

  • Patch redis redis systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • redis

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 68 mentions across 19 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 24 signals
  • Technical details provided in 59 signals
  • Disclosure: 39 classified signals
  • General: 10 classified signals
  • Peaked 11d ago at 21 mentions (2026-06-03); latest day: 3
  • 68 total mentions across 19 days

Affected systems

Vendors
Products
redis

Deep dive

Activity timeline68 mentions / 19d
05111621Mentions · 2026-05-05: 2Mentions · 2026-05-06: 1Mentions · 2026-05-07: 2Mentions · 2026-05-16: 1Mentions · 2026-05-20: 1Mentions · 2026-05-23: 1Mentions · 2026-06-02: 2Mentions · 2026-06-03: 21Mentions · 2026-06-04: 18Mentions · 2026-06-05: 4Mentions · 2026-06-08: 1Mentions · 2026-06-09: 2Mentions · 2026-06-10: 1Mentions · 2026-06-15: 4Mentions · 2026-07-07: 1Mentions · 2026-07-08: 1Mentions · 2026-08-18: 1Mentions · 2026-08-21: 1Mentions · 2026-08-26: 3PoC Mentioned / Linked · 2026-06-03: 2PoC Mentioned / Linked · 2026-08-21: 1PoC Mentioned / Linked · 2026-08-26: 3Exploit Tool / Code · 2026-06-03: 1Exploit Tool / Code · 2026-08-21: 1Exploit Tool / Code · 2026-08-26: 2Active Exploitation · 2026-06-04: 2Patch / Workaround · 2026-05-06: 1Patch / Workaround · 2026-05-07: 1Patch / Workaround · 2026-05-23: 1Patch / Workaround · 2026-06-03: 9Patch / Workaround · 2026-06-04: 6Patch / Workaround · 2026-06-05: 1Patch / Workaround · 2026-06-09: 1Patch / Workaround · 2026-06-15: 1Patch / Workaround · 2026-08-21: 1Patch / Workaround · 2026-08-26: 2Technical Details · 2026-05-05: 2Technical Details · 2026-05-06: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-16: 1Technical Details · 2026-05-23: 1Technical Details · 2026-06-03: 20Technical Details · 2026-06-04: 16Technical Details · 2026-06-05: 4Technical Details · 2026-06-08: 1Technical Details · 2026-06-09: 2Technical Details · 2026-06-15: 4Technical Details · 2026-07-07: 1Technical Details · 2026-07-08: 1Technical Details · 2026-08-21: 1Technical Details · 2026-08-26: 305-0505-0605-0705-1605-2005-2306-0206-0306-0406-0506-0806-0906-1006-1507-0707-0808-1808-2108-26
Signal classification6 categories
Disclosure
3957.4%
Patch
1116.2%
General
1014.7%
PoC
45.9%
Exploit
22.9%
Active Exploitation
22.9%
Referenced assets50 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-052
Disclosure2
2026-05-061
Patch1
2026-05-072
General1Patch1
2026-05-161
Disclosure1
2026-05-201
Disclosure1
2026-05-231
Patch1
2026-06-022
Disclosure1General1
2026-06-0321
Disclosure12Exploit1General3Patch4PoC1
2026-06-0418
Active Exploitation2Disclosure11General2Patch3
2026-06-054
Disclosure3Patch1
2026-06-081
Disclosure1
2026-06-092
Disclosure2
2026-06-101
General1
2026-06-154
Disclosure4
2026-07-071
Disclosure1
2026-07-081
General1
2026-08-181
General1
2026-08-211
Exploit1
2026-08-263
PoC3
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Disclosure

    🤖 An autonomous AI tool found a Redis RCE vulnerability that went unnoticed for more than two years. CVE-2026-23479 can let an authenticated user execute OS commands on the server. The flaw was introduced in Redis 7.2.0 and affected every stable branch until patches were released on May 5. 🔧 Details: https://thehackernews.com/2026/06/autonomous-ai-tool-finds-2-year-old-rce.html

    Post summary

    An autonomous AI tool discovered a two‑year‑old Redis RCE (CVE‑2026‑23479) that allows authenticated users to run OS commands; the flaw spans all 7.2.0+ stable branches and was patched on May 5, with additional details in the linked article.

    56252357345.0K
    1.9M followersView on X
  • Tim Becker@tjbecker
    General

    Hmm... this technique sounds familiar 👀 https://www.zeroday.cloud/blog/redis-cve-2026-23479-deep-dive https://t.co/g3WoHKUeH7

    Post summary

    The tweet links to a blog post about Redis CVE‑2026‑23479 but provides no technical, exploitation, or mitigation details.

    04050358.9K
    2.7K followersView on X
  • Xint@xint_official
    General

    CVE-2026-23479 in was one of the high severity bugs we found when we won at @wiz_io's ZeroDay Cloud competition. Be on the lookout soon for the technical deep dive on ZDC blog - this was a really interesting bug because of its subtlety. The complex interaction between portions of code far apart from each other in the codebase likely wouldn't have been noticed by humans or traditional SAST tools but can now be found in hours through AI with the right scaffolding Big thanks to the teams at @Redisinc and Wiz for the collaboration https://redis.io/blog/security-advisory-cve202623479-cve202625243-cve-2026-25588-cve202625589-cve-2026-23631/

    Post summary

    The tweet announces the discovery of CVE-2026-23479 during a zero‑day competition and hints at an upcoming deep dive, but provides no technical, exploit, or mitigation details.

    13032203.2K
    1.4K followersView on X
  • Xint@xint_official
    General

    Full technical deep dive available here: https://www.zeroday.cloud/blog/redis-cve-2026-23479-deep-dive

    Post summary

    The post references a technical deep dive blog on CVE‑2026‑23479 but provides no additional analysis or details in the text itself.

    010120133.1K
    1.4K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    PoC

    A public PoC exploits a Redis RCE use-after-free flaw tied to CVE-2026-23479, running system commands as the Redis server. Update to 8.8.2. #Redis #RCE #UseAfterFree #CVE202623479 #InfoSec https://securityonline.info/redis-rce-use-after-free-poc/

    Post summary

    A publicly available PoC demonstrates a Redis RCE use‑after‑free flaw (CVE-2026-23479); a link to the PoC and a version upgrade recommendation to 8.8.2 are provided.

    0912571.3K
    13.0K followersView on X
  • dbugs@ptdbugs
    Exploit

    A PoC/exploit has been discovered for vulnerability CVE-2026-23479 Vendor: redis Product: redis Description: Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from processCommandAndResetClient when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3. Link: https://github.com/v12-security/pocs/tree/main/redis/server #dbugs_vuln

    Post summary

    A functional PoC/exploit for CVE‑2026‑23479 in Redis has been released, detailing a use‑after‑free that results in remote code execution; patching occurs in version 8.6.3.

    1401881.6K
    3.6K followersView on X
  • Xint@xint_official
    Disclosure

    Get the full technical breakdown of this bug here: https://www.zeroday.cloud/blog/redis-cve-2026-23479-deep-dive

    Post summary

    The text directs readers to a blog post that offers a deeper technical analysis of the Redis CVE‑2026‑23479, but it contains no explicit PoC, exploit code, active‑exploitation notice, patch information, or technical details within the snippet.

    01014122.2K
    1.4K followersView on X
  • Nir Yehoshua@niryeho
    General

    Redis CVE-2026-23479 is not just a Stream issue. At Cipher Security Labs, we reconstructed the unblockClientOnKey() UAF and measured additional trigger surfaces. Key finding: stream-only ACL hardening is incomplete. Full research: https://ciphersecuritylabs.com/research/articles/a-measured-look-at-redis-cve-2026-23479-unblock-uaf-variant-surfaces-and-mitigation-reality

    Post summary

    Cipher Security Labs analyzes Redis CVE‑2026‑23479, detailing UAF trigger surfaces and ACL hardening gaps, but offers no PoC, exploit code, patch, or evidence of active exploitation.

    0408142.2K
    1.1K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    Redisで複数の深刻な脆弱性が修正。CVE-2026-23479、CVE-2026-25243、CVE-2026-25588、CVE-2026-25589のいずれもCVSSスコア7.7で、認証後ユーザによるメモリ破壊での遠隔コード実行。深刻度「中」の解放後メモリ使用CVE-2026-23631と併せ修正。 https://gbhackers.com/redis-security-flaws-expose-servers/

    Post summary

    The article reports that several Redis CVEs (2026‑23479, 25243, 25588, 25589, and 23631) have been patched, each with a CVSS score of 7.7 and allowing remote code execution via memory corruption after authentication.

    030841.6K
    7.6K followersView on X
  • Clandestine@akaclandestine
    Disclosure

    CVE-2026-23479 Redis RCE Vulnerability: A Two-Year Use-After-Free Flaw Discovered by AI | CIP Blog | Criminal IP https://www.criminalip.io/knowledge-hub/blog/35364

    Post summary

    A blog post announces a Redis RCE vulnerability discovered by AI, highlighting a two‑year use‑after‑free flaw.

    030551.6K
    63.3K followersView on X
  • yousukezan@yousukezan
    PoC

    Redisに、ヒープuse-after-freeからリモートコード実行につながる脆弱性「CVE-2026-23479」が見つかり、研究者がPoCを公開した。通常のTCPコマンド経由で悪用でき、Redis 8.8.2で修正された。 問題はブロック中クライアントの処理で発生するuse-after-freeだ。あるクライアントのコマンド再実行時、同じリスト上の別クライアントが解放され、次のループで解放済みメモリを有効なクライアントとして参照してしまう。 研究者はヒープ配置の調整とポインタ読み取りを組み合わせ、任意のシステムコマンド実行まで到達する攻撃チェーンを示した。モジュール読み込み、ファイル書き込み、再起動は不要で、通常のTCPコマンドだけを利用する。 ただし、攻撃にはCONFIG SETなどを実行できる権限が必要とされる。記事によると、実際の攻撃での悪用は確認されていない。 検証対象はRedis 8.8.0で、関連する元の脆弱性はRedis 7.2.0までさかのぼる。修正版8.8.2では別のメモリ破壊脆弱性CVE-2026-62356も修正された。 https://securityonline.info/redis-rce-use-after-free-poc/

    Post summary

    A researcher disclosed a heap use‑after‑free vulnerability (CVE‑2026‑23479) in Redis, released a PoC demonstrating remote code execution via normal TCP commands, and noted the issue is patched in 8.8.2 with no evidence of current in‑the‑wild exploitation.

    000331.6K
    16.0K followersView on X
  • Criminal IP@CriminalIP_US
    Disclosure

    🤖 AI uncovered a Redis vulnerability hidden in stable releases for nearly two years. CVE-2026-23479 is an authenticated use-after-free flaw that may lead to remote code execution under specific conditions. 🔎 Criminal IP findings: • ~74,000 internet-exposed Redis assets • 16,090 assets potentially affected • 2,166 assets running Redis 8.6.2 Authentication alone does not eliminate risk when exposed instances use weak credentials or excessive ACL permissions. 📄Read the full analysis: https://criminalip.io/knowledge-hub/blog/35364 #Redis #CyberSecurity #RCE #AttackSurface #ThreatIntelligence

    Post summary

    A previously undisclosed authenticated use‑after‑free vulnerability (CVE‑2026‑23479) in Redis could trigger remote code execution, and a large number of exposed instances have been identified.

    12010244
    4.9K followersView on X
  • Aikido Community Japan@AikidoCommJP
    Patch

    Redisの2年モノのRCE脆弱性(CVE-2026-23479)、コードレビューじゃなく自律型AIツールが発見したやつ。 自分も結構お世話になってるから調べてみた。 やることはシンプル: ① ポート(6379)の解放確認 ② 認証/権限の開放確認 ③ affectedなら fixed minorへ ネット非公開&生Redis触れない構成なら落ち着いて対応でOK。

    Post summary

    The post highlights a 2026 Redis RCE vulnerability, confirms a patch is available, and recommends port and authentication checks, but no PoC or exploit code is shared.

    20020151
    646 followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Disclosure

    Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479) https://thehackernews.com/2026/06/autonomous-ai-tool-finds-2-year-old-rce.html?m=1

    Post summary

    An autonomous AI tool identified a two‑year‑old remote code execution flaw (CVE‑2026‑23479) in Redis; no exploit, patch, or active exploitation details are provided.

    01012239
    12.3K followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Disclosure

    Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479) https://thehackernews.com/2026/06/autonomous-ai-tool-finds-2-year-old-rce.html?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    An autonomous AI tool has identified a 2‑year‑old RCE flaw in Redis (CVE‑2026‑23479); no PoC, exploit code, or patch is referenced.

    01011423
    194.6K followersView on X
  • GoCocoaAI@GoCocoaAI
    Disclosure

    An autonomous AI tool just found what two years of human code review missed: a use-after-free in Redis that reaches all the way to remote code execution. CVE-2026-23479. CVSS 8.8. The flaw was introduced in Redis 7.2.0 — May 2023 — and lived undetected in every stable branch until it was patched in 8.6.3 on May 5, 2026. Two years of cloud caches, session stores, rate-limiters, and message queues running exploitable code. We are nothing if not consistent. The mechanics: the vulnerability lives in the unblock_client flow, specifically the error-handling path from processCommandAndResetClient. When a blocked client is evicted during re-execution, an authenticated attacker can trigger the use-after-free and land OS command execution on the server. It's exactly the kind of subtle memory-management edge case that slips through code review — the kind of thing that requires systematic automated reasoning to catch, not a second pair of human eyes on a PR. The PR:L requirement — low-privilege authentication — is the one thing keeping this from being a catastrophic internet-wide story right now. An attacker needs a valid Redis credential first. That bar is lower than it sounds. Redis credentials leak in public repos, .env files, and misconfigured cloud deployments with depressing regularity. Redis is on the honor system, apparently. A few things worth underscoring beyond the headline CVE: This was a batch remediation, not a single-bug patch. The Redis security advisory covers at least four CVEs in the same drop — CVE-2026-23479, CVE-2026-25243, CVE-2026-25588, and CVE-2026-25589. If you're patching, patch the whole batch. No public PoC yet, no KEV listing, no confirmed wild exploitation — but that window is running. For a CVSS 8.8 RCE in a ubiquitous datastore, reconstructing the use-after-free from the patch diff is a standard adversarial workflow. Days to weeks, not months. The fact that an AI tool found it means the research community will want to reproduce it. That accelerates the timeline. Redis is the session and cache layer in a significant percentage of AI application backends — LLM inference pipelines, RAG stores, agent memory layers. Any deployment still running 7.2.0 through 8.6.2 should be treated as exposed until patched. The specific CVE matters. The broader signal matters more. Autonomous AI tools are now finding two-year-old critical flaws in production infrastructure at scale. Defenders using that capability find bugs before attackers do. Defenders not using it don't. That asymmetry is widening, and this is a proof point. CWE-416 — Use After Free | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N | Fixed: Redis 8.6.3

    Post summary

    An AI tool uncovered a use-after-free in Redis that allows authenticated remote code execution; the bug is fixed in 8.6.3, but no PoC or active exploitation exists yet and vulnerable versions remain exposed.

    30000130
    16 followersView on X
  • NilOps AI@nilops_ai
    Disclosure

    An autonomous AI bug-hunter just surfaced a 2-year-old use-after-free RCE in Redis (CVE-2026-23479) that sat unnoticed across every stable branch since 7.2.0. (1/3)

    Post summary

    An AI bug‑hunter uncovered a 2‑year‑old use‑after‑free remote code execution flaw in Redis (CVE‑2026‑23479), which had gone unnoticed across all stable branches since version 7.2.0.

    1001041
    7 followersView on X
  • IT SPARC Cast@ITSPARCCast
    Disclosure

    An autonomous AI security tool has discovered a critical Redis remote code execution vulnerability that remained hidden for more than two years. In this episode of IT SPARC Cast – CVE of the Week, @JohnBarger and @loudoggeek discuss CVE-2026-23479, why Redis is such a critical part of modern cloud infrastructure, and how AI is fundamentally changing vulnerability discovery, patch management, and enterprise security operations. Youtube Episode 39 - https://youtu.be/bmwj1Lw-Usk&utm_source=x&utm_medium=organic_social&utm_campaign=it_sparc_cast&utm_content=post YouTube Channel - https://www.youtube.com/@sparccast Apple Podcast Link - https://podcasts.apple.com/us/podcast/it-sparc-cast/id1765417728 Spotify Link - https://open.spotify.com/show/6bzVql2gpV6aVqX8oAAPls Amazon Podcast Link - https://music.amazon.com/podcasts/ea33693d-f555-4a7c-8c36-d321ab5cfed2/it-sparc-cast?ref=dm_sh_MPp9hVbtUJhlG3cN3xhfN5YN3 Acast Link - https://shows.acast.com/it-sparc-cast

    Post summary

    The tweet announces the discovery of a serious Redis RCE vulnerability (CVE-2026-23479) discussed in a podcast, without providing evidence of attacks, patches, or exploit details.

    00110193
    478 followersView on X
  • Mr.Rabbit@01ra66it
    Patch

    【Redisの認証済みRCE脆弱性 CVE-2026-23479】 Redisで、認証済みユーザーが任意OSコマンド実行につなげ得るCVE-2026-23479が修正されました。 この脆弱性はUse-After-Freeに関係し、Redis 7.2.0以降の一部バージョンに影響します。 認証が必要な脆弱性ではありますが、Redisがインターネットに露出している、デフォルトユーザー権限が強い、アプリケーション用アカウントに過剰なACLがある場合は影響が大きくなります。 SOCでは、Redisのバージョン、外部公開有無、`CONFIG`や`EVAL`の実行履歴、Redisホストからの不審なプロセス起動や外部通信を確認してください。 #Redis #CVE #RCE #脆弱性管理 #クラウドセキュリティ #SOC https://thehackernews.com/2026/06/autonomous-ai-tool-finds-2-year-old-rce.html

    Post summary

    The post announces that CVE-2026-23479, a use‑after‑free RCE in Redis, has been patched and outlines technical details and SOC hardening guidance, with no evidence of active exploitation or PoC.

    01001202
    3.7K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Redis ❗ CVE-2026-25589 ❗ CVE-2026-25588 ❗ CVE-2026-23479 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-redis/ https://t.co/YT4eMlEYZW

    Post summary

    The tweet announces three Redis-related CVEs and links to external sources for additional information, but it does not provide PoC, exploit code, active exploitation evidence, patch details, or technical specifics.

    01010120
    6.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appredisredis---

Explore more