Skip to content

Redis Security Updates Close Remote Code Execution Vulnerabilities

The Bottom Line: Redis patched four critical RCE vulnerabilities in versions 6.2, 7.4, 8.6, and 8.0 through released security updates.

Redis released seven security updates on July 23 after researchers demonstrated authenticated RCE exploits for multiple versions. The vulnerabilities require different Redis commands and modules for exploitation.

The affected Redis versions are 6.2.22, 7.4.9, 8.6.4, and 8.8.0. Security patches are available in versions 6.2.23, 7.2.15, and 7.4.10. All four exploit chains use the RESTORE command as a starting point; additionally, the streams-based chains require the EVAL and XGROUP commands, while the 8.8.0 variant also relies on EVAL and the bundled RedisBloom module.

According to Redis, the underlying memory management errors can lead to remote code execution. The attack requires existing authentication—unauthorized access is not possible.

For CISOs, this means Redis instances in their infrastructure running affected versions should be updated with priority. Special attention should be paid to systems where the RESTORE command is available and that additionally use the Streams modules or RedisBloom. The level of risk depends on who has access to Redis authentication in the environment.


Source: thehackernews.com · Published July 24, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: