Research · curated 24 Jul 2026

Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

Coverage timeline

24 Jul 2026thehackernews.com

Single-source research — first reported, latest, and curated coincide.

Why it matters

Kimi K3 agents autonomously finding real zero-days and producing functional RCE exploits demonstrates that agentic AI can now accelerate offensive vulnerability discovery and weaponization at scale, compressing the window defenders have before working exploits circulate.

Researchers report that Kimi K3 AI agents autonomously discovered multiple Redis zero-day memory-corruption flaws and built working authenticated RCE proof-of-concept exploits against stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0; the chains abuse RESTORE (plus EVAL/XGROUP and the RedisBloom module), and Redis shipped seven security releases on July 23 to fix the Streams shared-NACK use-after-free and RedisBloom/TDigest out-of-bounds writes. Defenders are advised to upgrade and revoke RESTORE from accounts that do not need it.