An exploit in our input validation has recently been discovered. This could allow a brute force attack to comprise and spoof input data for a given user. To resolve this issue, it is necessary to release a patch level version of the active versions of vBulletin.
The upgrade process is the same as previous patch level releases - simply download the patch from the Members Area, extract the files and upload to your webserver, overwriting the existing files. There is no upgrade script required.
As with all security-based releases, we recommend that all customers upgrade as soon as possible in order to prevent any potential damage resulting from the flaw being exploited.
If you are already running 3.7.6, 3.8.4 or 4.0.0, the process you...