CVE-2026-25243PoC(redis / redis)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch redis redis systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to execute RESTORE can supply a crafted serialized payload that triggers invalid memory access and may lead to remote code execution. A workaround is to restrict access to the RESTORE command with ACL rules. This is patched in version 8.6.3.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • redis

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 19 mentions across 11 observed days
  • Momentum state: rising

What's happening

  • Exploit tool or code specified in 7 signals
  • PoC mentioned or linked in 10 signals
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 16 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 6 mentions (2026-07-23); latest day: 2
  • 19 total mentions across 11 days

Affected systems

Vendors
Products
redis

Deep dive

Activity timeline19 mentions / 11d
02356Mentions · 2026-05-05: 2Mentions · 2026-05-06: 1Mentions · 2026-05-07: 1Mentions · 2026-05-21: 1Mentions · 2026-06-03: 2Mentions · 2026-06-04: 1Mentions · 2026-06-10: 1Mentions · 2026-07-13: 1Mentions · 2026-07-23: 6Mentions · 2026-07-25: 1Mentions · 2026-07-27: 2PoC Mentioned / Linked · 2026-06-10: 1PoC Mentioned / Linked · 2026-07-23: 6PoC Mentioned / Linked · 2026-07-25: 1PoC Mentioned / Linked · 2026-07-27: 2Exploit Tool / Code · 2026-07-23: 6Exploit Tool / Code · 2026-07-27: 1Patch / Workaround · 2026-05-06: 1Patch / Workaround · 2026-05-07: 1Patch / Workaround · 2026-06-03: 1Patch / Workaround · 2026-07-23: 2Patch / Workaround · 2026-07-25: 1Patch / Workaround · 2026-07-27: 1Technical Details · 2026-05-05: 2Technical Details · 2026-05-06: 1Technical Details · 2026-05-07: 1Technical Details · 2026-06-03: 1Technical Details · 2026-06-10: 1Technical Details · 2026-07-13: 1Technical Details · 2026-07-23: 6Technical Details · 2026-07-25: 1Technical Details · 2026-07-27: 205-0505-0605-0705-2106-0306-0406-1007-1307-2307-2507-27
Signal classification5 categories
PoC
736.8%
Disclosure
526.3%
Patch
315.8%
General
315.8%
Exploit
15.3%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-05-052
Disclosure2
2026-05-061
Disclosure1
2026-05-071
Patch1
2026-05-211
General1
2026-06-032
Disclosure1General1
2026-06-041
General1
2026-06-101
Disclosure1
2026-07-131
Exploit1
2026-07-236
PoC6
2026-07-251
Patch1
2026-07-272
Patch1PoC1
Full discourse19 posts
  • Nicolas Krassas@Dinosn
    PoC

    RCE PoC - CVE-2026-25243 — Redis RESTORE zipmap double-free → remote code execution (ASLR on). https://github.com/dinosn/CVE-2026-25243

    Post summary

    The text announces a proof‑of‑concept exploit for CVE‑2026‑25243, providing a GitHub link to the code and describing the double‑free vulnerability in Redis RESTORE that leads to remote code execution.

    13501828212.1K
    160.9K followersView on X
  • ThreatWire@ThreatWire_
    PoC

    🚨 A public PoC has been released for CVE-2026-25243 affecting Redis. The flaw could allow authenticated remote code execution (RCE) via a crafted RESTORE payload. Fixed in Redis 8.6.3. 🔗 https://github.com/berabuddies/redis-poc #Redis #RCE #CVE #CyberSecurity

    Post summary

    The tweet announces a publicly available PoC demonstrating authenticated RCE in Redis via a crafted RESTORE payload for CVE-2026-25243, and notes that the issue is fixed in Redis 8.6.3.

    14701366123.7K
    1.4K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    Redis seems to be a project to test LLM security audit harness. I'm opening my past work also. Reliable remote code execution from a single crafted RESTORE on jemalloc Redis https://github.com/dinosn/CVE-2026-25243-debugfree

    Post summary

    The post shares a GitHub repository containing a proof‑of‑concept that demonstrates remote code execution in Redis through a crafted RESTORE operation on jemalloc, highlighting the vulnerability’s exploitation potential.

    38051185.3K
    160.9K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    PoC

    Discover how new Redis RCE exploit PoC code bypasses fixes for CVE-2026-25243 and CVE-2026-25589 across multiple Redis versions. #Redis #Cybersecurity #RCE #Vulnerability #ExploitPoC http://meterpreter.org/redis-rce-exploit-poc/

    Post summary

    A proof‑of‑concept RCE exploit for Redis that bypasses the latest patches for CVE-2026-25243 and CVE-2026-25589 is disclosed, with a link to the PoC code.

    050191871
    13.0K followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-25243 PT ID: PT-2026-37092 Vendor: redis Product: redis Description: Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to execute RESTORE can supply a crafted serialized payload that triggers invalid memory access and may lead to remote code execution. A workaround is to restrict access to the RESTORE command with ACL rules. This is patched in version 8.6.3. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-37092 • https://github.com/berabuddies/redis-poc #dbugs_vuln

    Post summary

    A proof‑of‑concept for CVE‑2026‑25243 in Redis was released, showing how a crafted RESTORE payload can lead to remote code execution; the issue is mitigated by ACL restrictions and patched in 8.6.3.

    010125790
    3.4K followersView on X
  • Zerotistic@gegrgtezrze
    General

    I actually found one of those RCE (CVE-2026-25243)! But it was marked as duplicate because I was too slow to discover it 😟 They seem to use a different technique than me for RCE, maybe I will write a technical detail for mine… https://t.co/xJJFJLoWyD

    Post summary

    The user reports discovering a RCE CVE-2026-25243 but provides no proof‑of‑concept, exploit, patch, or technical detail, categorizing the post as a general mention.

    21111310.8K
    320 followersView on X
  • kokumօtօ@__kokumoto
    Patch

    Redisで複数の深刻な脆弱性が修正。CVE-2026-23479、CVE-2026-25243、CVE-2026-25588、CVE-2026-25589のいずれもCVSSスコア7.7で、認証後ユーザによるメモリ破壊での遠隔コード実行。深刻度「中」の解放後メモリ使用CVE-2026-23631と併せ修正。 https://gbhackers.com/redis-security-flaws-expose-servers/

    Post summary

    The article announces that several Redis CVEs (including CVE-2026‑23479, ‑25243, ‑25588, ‑25589, and ‑23631) have been patched, with no mention of PoC or active exploitation.

    030841.6K
    7.6K followersView on X
  • GoCocoaAI@GoCocoaAI
    Disclosure

    An autonomous AI tool just found what two years of human code review missed: a use-after-free in Redis that reaches all the way to remote code execution. CVE-2026-23479. CVSS 8.8. The flaw was introduced in Redis 7.2.0 — May 2023 — and lived undetected in every stable branch until it was patched in 8.6.3 on May 5, 2026. Two years of cloud caches, session stores, rate-limiters, and message queues running exploitable code. We are nothing if not consistent. The mechanics: the vulnerability lives in the unblock_client flow, specifically the error-handling path from processCommandAndResetClient. When a blocked client is evicted during re-execution, an authenticated attacker can trigger the use-after-free and land OS command execution on the server. It's exactly the kind of subtle memory-management edge case that slips through code review — the kind of thing that requires systematic automated reasoning to catch, not a second pair of human eyes on a PR. The PR:L requirement — low-privilege authentication — is the one thing keeping this from being a catastrophic internet-wide story right now. An attacker needs a valid Redis credential first. That bar is lower than it sounds. Redis credentials leak in public repos, .env files, and misconfigured cloud deployments with depressing regularity. Redis is on the honor system, apparently. A few things worth underscoring beyond the headline CVE: This was a batch remediation, not a single-bug patch. The Redis security advisory covers at least four CVEs in the same drop — CVE-2026-23479, CVE-2026-25243, CVE-2026-25588, and CVE-2026-25589. If you're patching, patch the whole batch. No public PoC yet, no KEV listing, no confirmed wild exploitation — but that window is running. For a CVSS 8.8 RCE in a ubiquitous datastore, reconstructing the use-after-free from the patch diff is a standard adversarial workflow. Days to weeks, not months. The fact that an AI tool found it means the research community will want to reproduce it. That accelerates the timeline. Redis is the session and cache layer in a significant percentage of AI application backends — LLM inference pipelines, RAG stores, agent memory layers. Any deployment still running 7.2.0 through 8.6.2 should be treated as exposed until patched. The specific CVE matters. The broader signal matters more. Autonomous AI tools are now finding two-year-old critical flaws in production infrastructure at scale. Defenders using that capability find bugs before attackers do. Defenders not using it don't. That asymmetry is widening, and this is a proof point. CWE-416 — Use After Free | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N | Fixed: Redis 8.6.3

    Post summary

    An AI tool uncovered a use‑after‑free RCE vulnerability in Redis (CVE‑2026‑23479) that has a patch available; no PoC, exploit code, or active exploitation has yet been reported.

    30000130
    16 followersView on X
  • T1erOne@tieroneforum
    Exploit

    (CVE-2026-25243) Эксплуатация Redis 8.6: от UAF в Stream PEL до выполнения кода https://tier1.life/thread/406 http://tieronemkfevyizxcnt355agysp2iemvhon6iyclwrc7yuc7oszgzrid.onion/thread/406 #articles @gegrgtezrze

    Post summary

    The text indicates that CVE-2026-25243, a Use‑After‑Free flaw in Redis 8.6, has been exploited to enable code execution, though it does not provide explicit PoC code, patch information, or evidence of live attacks.

    00011345
    259 followersView on X
  • Mahmoud Jadaan@mjadaaan
    PoC

    CVE-2026-25243 — Redis RESTORE zipmap double-free → remote code execution https://github.com/dinosn/CVE-2026-25243

    Post summary

    The post highlights CVE‑2026‑25243, a Redis RESTORE zipmap double‑free that allows remote code execution, and links to a GitHub repository with a PoC.

    0001060
    42 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-8732 2 - CVE-2026-23631 3 - CVE-2026-25243 4 - CVE-2026-46333 5 - CVE-2026-23479 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists five trending CVE identifiers without providing any additional technical or mitigation information.

    00010136
    1.7K followersView on X
  • 𝔻𝟘𝟠𝟙ℕ𝔾@HEXD__30__30
    Patch

    🚨CVE-2026-25243 — authenticated RCE in Redis (fixed in 8.6.3). A crafted RESTORE payload triggers a double-free in the RDB deserializer, leading to code execution in the redis-server process. A public PoC is now circulating. If you're not on 8.6.3+, patch now. #Redis #RCE #CVE

    Post summary

    CVE-2026-25243 is an authenticated RCE in Redis caused by a double‑free in the RESTORE payload; a public PoC circulates and users are urged to patch to version 8.6.3 or newer.

    0000044
    24 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨High - Redis Double-Free RCE via RESTORE and XGROUP DELCONSUMER (CVE-2026-66373) In Redis before 8.8.0, an authenticated attacker able to run RESTORE can supply a payload where the same stream NACK (pending entry) is referenced by more than one consumer. Deleting both consumers with XGROUP DELCONSUMER then triggers a double free, corrupting the heap and enabling remote code execution. The bug exists because of an incomplete fix for CVE-2026-25243, and a public PoC is available. Exploitation requires an authenticated client with access to RESTORE and has high attack complexity, so hardened, ACL-restricted deployments are less exposed. CVSS 7.5. 👉Upgrade Redis to 8.8.0. Where you can't patch, restrict RESTORE and stream commands via ACLs for low-trust clients.

    Post summary

    The tweet announces a double‑free RCE vulnerability (CVE‑2026‑66373) in Redis, provides technical details and a public PoC, and recommends upgrading to 8.8.0 or restricting RESTORE/stream commands via ACLs.

    0000094
    254 followersView on X
  • ✪ 𝕱𝖆𝖍𝖆𝖉@fad_777
    PoC

    ثغرة Redis قد تتجاوز ASLR. إثبات مفهوم لـ CVE 2026 25243 يوضح خلل double free في RESTORE zipmap قد يقود إلى تنفيذ تعليمات برمجية عن بُعد. Redis RCE PoC worth reviewing. CVE 2026 25243 shows a RESTORE zipmap double free that can lead to remote code execution even with ASLR enabled. A clear reminder that mitigations reduce risk, but do not erase exploitability. https://github.com/dinosn/CVE-2026-25243 #Redis #CVE202625243 #ExploitDevelopment

    Post summary

    The tweet announces a double‑free RCE vulnerability in Redis (CVE‑2026‑25243) and shares a PoC on GitHub, but does not report active exploitation or a patch.

    0000049
    79 followersView on X
  • CVE Playground@cveplayground
    Disclosure

    CVE-2026-25243 is a double-free vulnerability in Redis's RDB deserialization logic triggered via the RESTORE command.2 independent bugs create overlapping heap objects that an attacker can exploit for arbitrary read/write and full remote code execution. https://cveplayground.com/blog/cve-2026-25243-redis-restore-double-free-rce

    Post summary

    The post announces a double‑free vulnerability in Redis triggered via the RESTORE command that permits arbitrary read/write and full remote code execution, providing technical details and linking to further information.

    0000054
    14 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-25243: Redis RESTORE Serialized Value Validation Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04hvnNw0

    Post summary

    The text is a headline reference to a Redis RESTORE validation bug (CVE-2026-25243) without detailed technical information or evidence of exploitation.

    0000045
    31 followersView on X
  • Cyber Netsec IO@NetSecIO
    Disclosure

    ⚠️ High-Severity Redis Flaw: A heap buffer overflow (CVE-2026-25243) in the RESTORE command could allow for RCE on Redis servers. Affects versions up to 8.6.3. Upgrade now or restrict access via ACLs! #Redis #CyberSecurity #Vulnerability https://t.co/nuzxjXgh59

    Post summary

    The tweet announces a new heap buffer overflow vulnerability (CVE‑2026‑25243) in Redis’s RESTORE command that could enable remote code execution, affecting versions up to 8.6.3, and advises users to upgrade or apply ACL restrictions.

    0000046
    46 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-25243 Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticate… https://www.cve.org/CVERecord?id=CVE-2026-25243 ----- Traducción: CVE-2026-25243 Red… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑25243, a validation flaw in Redis’s RESTORE command affecting versions up to 8.6.3. No PoC, exploit, patch, or evidence of active exploitation is provided.

    0000033
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25243 Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticate… https://www.cve.org/CVERecord?id=CVE-2026-25243

    Post summary

    CVE-2026-25243 affects Redis versions up to 8.6.3, where the RESTORE command fails to validate serialized values; no exploit, patch, or active exploitation information is provided.

    00000156
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appredisredis---

Explore more