[NEW] [high] Redis: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in Redis to bypass security measures, impersonate other users, manipulate data, disclose confidential information, corrupt memory, potentially execute arbitrary code, and cause denial-of-service conditions.
CSIRTS triage
- What
- Multiple vulnerabilities enable security bypass, user impersonation, data manipulation, information disclosure, memory corruption, arbitrary code execution, and denial-of-service.
- Who is affected
- Any Redis deployment exposed to untrusted network access.
- Urgency
- High severity; multiple critical attack vectors including RCE and DoS; apply patches as soon as available regardless of exploitation status.
- Action
- Patch Redis immediately upon availability; restrict network access to Redis to trusted hosts only until patched.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Redis
Get an email when a new Redis advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2869
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-62356 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for Redis
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[UPDATE] [hoch] Redis: Mehrere Schwachstellencert-bund · 2026-09-14
- medium[UPDATE] [mittel] Redis: Schwachstelle ermöglicht Codeausführungcert-bund · 2026-09-11
- medium[UPDATE] [mittel] Redis: Schwachstelle ermöglicht Denial of Service und Offenlegung von Informationencert-bund · 2026-09-10
- criticalGHSA-w6f5-v2h6-g786: Predis: Redis command injection and denial of service via CRLF smuggling in pipelined com…ghsa · 2026-09-08
- criticalCVE-2026-84372: Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-…nvd · 2026-09-01
- unknownRedis security advisory (AV26-859)cccs · 2026-08-28
More from CERT-Bund (BSI) Security Advisories
- medium[NEU] [mittel] Microsoft Edge: Schwachstelle ermöglicht Cross-Site Scripting2026-09-14
- medium[NEU] [mittel] Citrix Systems Workspace App Windows: Mehrere Schwachstellen ermöglichen nicht spezifizierten A…2026-09-14
- medium[NEU] [mittel] wpa_supplicant: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen2026-09-14
- medium[NEU] [mittel] WP Royal Royal Elementor Addons: Schwachstelle ermöglicht Offenlegung von Informationen2026-09-14
- low[UPDATE] [niedrig] 7-Zip: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen2026-09-14