A critical use-after-free vulnerability (CVE-2026-81934) has been identified in Redis within the 'tlsProcessPendingData()' function, which manages the TLS pending-data list. The vulnerability is present when Redis is configured with TLS support. A remote, unauthenticated attacker can potentially exploit this flaw to execute arbitrary commands with the privileges of the Redis server process. The vulnerability affects multiple Redis versions and has been patched in Redis 8.2.9, 8.4.6, 8.6.6, 8.8.2, and 8.10.1. A proof-of-concept exploit has been publicly released on GitHub. Organizations running Redis with TLS enabled should prioritize upgrading to the patched versions immediately to mitigate the risk of unauthorized remote code execution.