CVE-2026-81934 – Redis
CVSS 7.1
IMPORTANT
Zero Day – Immediate Deployment
“A TLS memory-safety flaw can turn unauthenticated network access into command execution on the Redis host.”
Redis contains a High-severity use-after-free vulnerability in tlsProcessPendingData() when TLS support is enabled. CVE-2026-81934 may allow a remote unauthenticated attacker to execute arbitrary commands with the privileges of the Redis server. The CVSS score is 7.1, which is High severity.
Public proof-of-concept material is available for the vulnerability.
Key Details
- Attack Vector
- Adjacent
- Attack Complexity
- High
- Privileges Required
- Low
- User Interaction
- None
- CWE Classification
- CWE-416
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.