DSA-6406-1 php8.4 - security update
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in denial of service, SQL injection, information disclosure or the execution of arbitrary code. https://security-tracker.debian.org/tracker/DSA-6406-1
CSIRTS triage
- What
- Multiple security issues in PHP allow denial of service, SQL injection, information disclosure, and arbitrary code execution.
- Who is affected
- Systems running PHP 8.4.
- Urgency
- High; arbitrary code execution is a critical risk.
- Action
- Upgrade PHP to the patched version referenced in DSA-6406-1.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch PHP
Get an email when a new PHP advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00317.html
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-72600.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-175430.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-175440.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-7260 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-17543 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-17544 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownUSN-8734-1: PHP vulnerabilitiesubuntu
- high[UPDATE] [hoch] PHP: Mehrere Schwachstellencert-bund
- unknownPHP Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in PHP (July 31, 2026)cert-fr-avis
- mediumCVE-2026-7260: Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C st…nvd
- criticalCVE-2026-17544: Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap …nvd
- criticalCVE-2026-17543: Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL i…nvd
- criticalCVE-2026-17543: SQL injection in ext-pgsql via E'...' backslash breakoutmsrc
- mediumCVE-2026-7260: Stack overflow in phar with circular symlinksmsrc
More from Debian Security Advisories
- unknownDSA-6489-1 gst-plugins-base1.0 - security update2026-09-08
- unknownDSA-6488-1 jbig2dec - security update2026-09-07
- unknownDSA-6487-1 strongswan - security update2026-09-07
- unknownDSA-6485-1 tryton-server - security update2026-09-06
- unknownDSA-6486-1 libde265 - security update2026-09-06