A critical vBulletin vulnerability can let unauthenticated attackers execute arbitrary PHP code on vulnerable forum servers. The flaw, tracked as CVE-2026-61511, affects several releases in the 5.x and 6.x branches and now has a public proof-of-concept exploit. Administrators should apply the available security updates immediately. Internet-facing forums are especially exposed because attackers can target the…