Redis RCE Exploit: Kimi K3 Agents Find Zero-Days & Build Exploits (2026 Update) (2026)

Redis, a popular in-memory data store, has been in the news again, but this time with a twist. Researchers have discovered a critical vulnerability in Redis, but it's not just any bug. It's a complex, multi-layered exploit that involves multiple paths and requires a deep understanding of Redis' inner workings. The story begins with the discovery of two distinct paths through the Redis RESTORE command, leading to remote code execution (RCE) vulnerabilities. These vulnerabilities were found by AI-powered agents, specifically the Kimi K3 agents, which reportedly found 19 Redis zero-days in about 90 minutes and the Redis 8.8.0 exploit in just 27 minutes. However, the reliability of these claims is questionable, as Redis's public record confirms the flaws and fixes without validating the claimed zero-day count or the agents' independence. The first path is in Redis Streams, where a corrupt RDB object can make two consumers point to the same pending-entry record, leading to a shared-ownership bug. The second path is in the RedisBloom TDigest RDB loader, where an out-of-bounds write occurs due to a mismatch between the allocated memory and the attacker-controlled capacity field. Both paths lead to arbitrary memory access, allowing attackers to execute system calls and potentially gain full control of the Redis server. The impact of these vulnerabilities is significant, as they can be exploited to execute arbitrary code on the server, potentially leading to data breaches, system compromises, and other malicious activities. The discovery of these vulnerabilities has prompted Redis to release seven security updates, including Redis 6.2.23, 7.2.15, 7.4.10, 8.2.8, 8.4.5, 8.6.5, and 8.8.1, to address the issues. However, the vulnerability remains unpatched in Redis 6.2.22 and 7.4.9, which were the May security updates that Redis told users to install. The vulnerability is assigned the CVE-2026-25589 identifier, but Redis maps it to RedisBloom memory corruption during the RESTORE command, not the Streams shared-NACK flaw. As of July 24, 2026, no separate NVD record for the July shared-NACK or TDigest findings was found, and no entry for either identifier was found in CISA's Known Exploited Vulnerabilities catalog. The disclosure of these vulnerabilities follows another AI-discovered Redis RCE flaw patched in May. The story raises important questions about the reliability of AI-powered vulnerability discovery tools and the importance of thorough testing and validation in software development. It also highlights the need for organizations to keep their software up-to-date and to implement robust security measures to protect against potential exploits. In conclusion, the discovery of these vulnerabilities in Redis highlights the ongoing challenges in securing software systems and the need for continuous vigilance and improvement in security practices. It also underscores the importance of transparency and accountability in the security community, as well as the need for collaboration and information sharing to address emerging threats effectively.

Redis RCE Exploit: Kimi K3 Agents Find Zero-Days & Build Exploits (2026 Update) (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Chrissy Homenick

Last Updated:

Views: 5629

Rating: 4.3 / 5 (74 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Chrissy Homenick

Birthday: 2001-10-22

Address: 611 Kuhn Oval, Feltonbury, NY 02783-3818

Phone: +96619177651654

Job: Mining Representative

Hobby: amateur radio, Sculling, Knife making, Gardening, Watching movies, Gunsmithing, Video gaming

Introduction: My name is Chrissy Homenick, I am a tender, funny, determined, tender, glorious, fancy, enthusiastic person who loves writing and wants to share my knowledge and understanding with you.