Threat Advisory

Redis RCE Flaw Lets Authenticated Attacker Run Code

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting Redis versions and Patch have been identified in Redis, a widely used in-memory data store. A public proof-of-concept now targets.

CVE-2026-66373 (CVSS 7.5 — High Severity): This vulnerability is caused by a double-free bug in the RESTORE command of Redis Streams, which allows an attacker to corrupt the heap and execute arbitrary code with system calls.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting Redis versions and Patch have been identified in Redis, a widely used in-memory data store. A public proof-of-concept now targets.

CVE-2026-66373 (CVSS 7.5 — High Severity): This vulnerability is caused by a double-free bug in the RESTORE command of Redis Streams, which allows an attacker to corrupt the heap and execute arbitrary code with system calls.[emaillocker id="1283"]

CVE-2026-25243: This earlier patch did not fully close the RESTORE memory-corruption path, so the same class of attack returned. These vulnerabilities collectively present a significant risk for authenticated attackers who can access Redis. These vulnerabilities collectively present a significant risk for authenticated attackers who can access Redis.

These vulnerabilities collectively present a significant risk for authenticated attackers who can access Redis.

RECOMMENDATION:

We recommend you to update Redis to version 8.8.0.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu