CVE-2026-81934: Redis Vulnerability in TLS Data Processing
This text was generated using artificial intelligence (AI).On August 27, 2026, CVE-2026-81934 released for Redis. The vulnerability affects the function tlsProcessPendingData, which processes the list of outstanding TLS data if Redis is configured with TLS support. After a fix from the CNA on August 31, 2026, the CVSS score is 7.5 (v4.0) or 7.1 (v3.1), severity high; originally, the vulnerability was rated 9.8 (critical).
According to the corrected CVSS vector, an attack requires access from the adjacent network, low privileges, and high attack complexity. If successful, arbitrary commands can be executed with the privileges of the Redis server. According to the release notes, the error occurs when a command closes another pending connection. Therefore, Redis instances with TLS configuration are particularly relevant for prioritization.
Vulnerability: CVE-2026-81934 (CVSS 7.5 (v4.0) / 7.1 (v3.1), high – corrected on August 31, 2026; previously 9.8)
Status: No active abuse has been documented
Affected Function and Potential Impact
CVE-2026-81934 is a use-after-free vulnerability in tlsProcessPendingData. The function processes pending TLS data from a Redis instance.
The documented potential impact is the execution of arbitrary commands within the Redis server's authorization context. The TLS configuration is a prerequisite for the vulnerability described.
For organizations in Germany and Austria that fall under NIS-2 or the Austrian NISG, exploiting such a vulnerability can trigger reporting obligations. In Switzerland, the reporting obligation applies according to the revised Information Security Act (ISG) to operators of critical infrastructures. Furthermore, in the case of a security-related incident involving personal data in the EU, the 72-hour reporting obligation according to GDPR Article 33 applies. Operators of critical infrastructures should therefore treat the patch status of Redis instances with TLS configuration as a high priority.
Revised Redis Releases
Fixed releases for CVE-2026-81934 are available for several Redis branches:
Redis 6.2.24
Redis 7.2.16
Redis 7.4.11
Redis 8.2.9
Redis 8.4.6
Redis 8.6.6
Redis 8.8.2
Redis 8.10.1
Organizations should check the patch status and vulnerability status of their Redis instances. Systems with TLS configuration should be prioritized.
Risk Mitigation Measures
The following steps are based on the documented vulnerability and the provided fixes:
Identify Redis instances with TLS configuration.
Check for a patch and determine whether CVE-2026-81934 affects your system.
Update affected systems per branch on Redis 6.2.24, 7.2.16, 7.4.11, 8.2.9, 8.4.6, 8.6.6, 8.8.2, or 8.10.1.
Do not expose Redis instances without authentication or network segmentation.
Establish continuous vulnerability and vendor risk monitoring.
Verifying authentication and network segmentation complements the process of updating the affected Redis instances. Both measures address the availability of a service, while the patch status addresses the technical vulnerability in the Redis branch being used.
Visibility of Redis Services
LocateRisk EASM can identify Redis instances among enterprise assets and highlight accessible services for technical prioritization. For CVE-2026-81934, the combination of the Redis service, TLS configuration, and accessibility is relevant. In addition to actively used systems, the continuous external perspective also captures forgotten or uninventoried instances—such as those from shadow IT or discontinued projects—that are often not tracked in internal asset management.
However, the presence of a visible Redis instance does not prove that a specifically vulnerable version is in use. Therefore, assessing CVE-2026-81934 requires checking the patch status as well as verifying the TLS configuration, authentication, and network segmentation.
Am I affected?
Affected is Redis with TLS configuration; the vulnerability has been fixed in 6.2.24, 7.2.16, 7.4.11, 8.2.9, 8.4.6, 8.6.6, 8.8.2, and 8.10.1. Anyone wanting to know if Redis is visible in their externally accessible infrastructure can use the CVE Quick Check Use the tool at the end of this article: It shows exposed systems and the software that is visible from the outside.
It is not always possible to determine the specific version that has been installed from the outside—the key factor is comparing it with the manufacturer's advisory.
CVE-2026-81934 is a use-after-free vulnerability in the Redis function tlsProcessPendingData, which processes outstanding TLS data. According to the corrected CVSS vector of the CNA, an attack requires access from the adjacent network and low privileges; if successful, arbitrary commands can be executed with the privileges of the Redis server. Since August 31, 2026, it has been rated CVSS 7.5 (v4.0) or 7.1 (v3.1), severity high; originally, 9.8 (critical) was indicated.
This vulnerability affects Redis instances that are configured with TLS support. Systems without TLS configuration are not affected by this vulnerability.
Cleaned releases are available for multiple branches: Redis 6.2.24, 7.2.16, 7.4.11, 8.2.9, 8.4.6, 8.6.6, 8.8.2, and 8.10.1. Administrators should identify the Redis version in use and update to the appropriate cleaned release.
Status: August 28, 2026, updated on September 30, 2026 (re-evaluation of the CVSS classification by the CNA). This article is for general informational purposes only and does not constitute legal, security, or action advice in individual cases. The security situation and patch availability may have changed since publication; the linked vendor advisory is always authoritative. Despite careful research, we assume no responsibility for the currentness, correctness, and completeness.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2026-81934
Passive Assessment
Information About the CVEfound or not found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.