CVE-2026-81934 – Redis

CVSS 7.1 IMPORTANT Zero Day – Immediate Deployment

“A TLS memory-safety flaw can turn unauthenticated network access into command execution on the Redis host.”

Redis contains a High-severity use-after-free vulnerability in tlsProcessPendingData() when TLS support is enabled. CVE-2026-81934 may allow a remote unauthenticated attacker to execute arbitrary commands with the privileges of the Redis server. The CVSS score is 7.1, which is High severity.

Public proof-of-concept material is available for the vulnerability.

Key Details

Attack Vector
Adjacent
Attack Complexity
High
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-416
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.