Research & Notes

Field notes on AI and the economics of exploitation.

CVE-2026-61511 · vbulletin · rce · exploit-reproduction · ai-exploit

CVE-2026-61511: vBulletin Unauthenticated RCE (Template Eval Injection), Reproduced for $1.61

CVE-2026-61511 is a critical (CVSS 9.8) pre-auth remote code execution bug in vBulletin's template engine. Here is what it is, how the exploit works, and how our lab reproduced it in 12m 36s for $1.61.

CVE-2026-66066 · rails · exploit-reproduction · ai-exploit

CVE-2026-66066: Rails ActiveStorage Arbitrary File Read (XXE), Reproduced for $0.87

CVE-2026-66066 is a critical (CVSS 9.5) arbitrary file read in Rails ActiveStorage via libvips. We reproduced a working XXE exploit in 7m 29s for $0.87 — and why 'we've seen no AI-driven attacks' is a lagging indicator.

announcement

Introducing Vulnerability Research Labs (VRL)

Why we started VRL: to fight FUD with actual research and data, build in the open, and hand defenders practical tools. Independently verified in partnership with Loginsoft.

Get research & product updates

No spam. Unsubscribe anytime. See our privacy policy.

Vulnerability Research Labs
Vulnerability Research Labs (VRL) is a research unit of Quantro Security, in partnership with Loginsoft.
Updated 17 Jul 2026 · n=3,029 · vulnerabilityresearchlabs.ai
© 2026 Vulnerability Research Labs (VRL). All rights reserved.