Multiple vulnerabilities in PHP (July 31, 2026)
Multiple vulnerabilities have been discovered in PHP. Some of them allow an attacker to cause SQL injection (SQLi), denial of service and an unspecified security issue by the editor.
CSIRTS triage
- What
- Multiple vulnerabilities in PHP including SQL injection, denial of service, and an unspecified security issue.
- Who is affected
- All PHP installations running vulnerable versions.
- Urgency
- High; SQL injection vulnerabilities in core PHP require immediate updates to prevent database compromise.
- Action
- Update PHP to the latest patched version that addresses CVE-2026-7260, CVE-2026-17543, CVE-2026-17544, and CVE-2026-9672.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch PHP
Get an email when a new PHP advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0952/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-72600.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-175430.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-175440.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-7260 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-17543 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-17544 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9672 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownUSN-8743-1: PHP vulnerabilitiesubuntu
- unknownUSN-8734-1: PHP vulnerabilitiesubuntu
- high[UPDATE] [hoch] PHP: Mehrere Schwachstellencert-bund
- unknownPHP Multiple Vulnerabilitieshkcert
- unknownDSA-6409-1 libgd2 - security updatedebian
- unknownDSA-6406-1 php8.4 - security updatedebian
- mediumCVE-2026-7260: Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C st…nvd
- criticalCVE-2026-17544: Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap …nvd
- criticalCVE-2026-17543: Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL i…nvd
- criticalCVE-2026-17543: SQL injection in ext-pgsql via E'...' backslash breakoutmsrc
- mediumCVE-2026-7260: Stack overflow in phar with circular symlinksmsrc
Recent advisories for PHP
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-88023: Improper neutralization of special elements in data query logic in the GridFS component of the…nvd · 2026-09-10
- highCVE-2026-73699: FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticate…nvd · 2026-09-10
- highCVE-2026-79987: A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permiss…nvd · 2026-09-10
- highCVE-2026-81784: Unauthenticated PHP Object Injection in Wise Chat <= 3.4 versions.nvd · 2026-09-10
- unknownUSN-8743-1: PHP vulnerabilitiesubuntu · 2026-09-10
- highCVE-2026-87930: MaxSite CMS through 109.6 passes the ci_session cookie to unserialize() without class restrict…nvd · 2026-09-09
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans HPE Aruba Networking ClearPass Policy Manager (10 septembre 2026)2026-09-10
- unknownMultiples vulnérabilités dans les produits Check Point (10 septembre 2026)2026-09-10
- unknownMultiples vulnérabilités dans Moodle (10 septembre 2026)2026-09-10
- unknownMultiples vulnérabilités dans les produits Palo Alto Networks (10 septembre 2026)2026-09-10
- unknownVulnérabilité dans Apereo CAS (10 septembre 2026)2026-09-10