Redis has patched a use-after-free in its blocking-client code
that lets an authenticated user run arbitrary OS commands on the
machine hosting the database. The flaw was found by an autonomous
AI tool built to hunt bugs in large codebases. Tracked as
CVE-2026-23479, the flaw was introduced in Redis 7.2.0 and remained
in every stable branch until the May 5 fixes, unnoticed for over
two years.
Read more https://thehackernews.com/2026/06/autonomous-ai-tool-finds-2-year-old-rce.html

