Multiple vulnerabilities in PHP (July 31, 2026)
Multiple vulnerabilities have been discovered in PHP. Some of them allow an attacker to cause SQL injection (SQLi), denial of service and an unspecified security issue by the editor.
CSIRTS triage
- What
- Multiple vulnerabilities in PHP including SQL injection, denial of service, and an unspecified security issue.
- Who is affected
- All PHP installations running vulnerable versions.
- Urgency
- High; SQL injection vulnerabilities in core PHP require immediate updates to prevent database compromise.
- Action
- Update PHP to the latest patched version that addresses CVE-2026-7260, CVE-2026-17543, CVE-2026-17544, and CVE-2026-9672.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch PHP
Get an email when a new PHP advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0952/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-72600.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-175430.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-175440.52% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-7260 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-17543 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-17544 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9672 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [high] PHP: Multiple Vulnerabilitiescert-bund
- unknownPHP Multiple Vulnerabilitieshkcert
- unknownDSA-6409-1 libgd2 - security updatedebian
- unknownDSA-6406-1 php8.4 - security updatedebian
- mediumCVE-2026-7260: Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C st…nvd
- criticalCVE-2026-17544: Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap …nvd
- criticalCVE-2026-17543: Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL i…nvd
Recent advisories for PHP
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[UPDATE] [high] PHP: Multiple Vulnerabilitiescert-bund · 2026-08-07
- highCVE-2026-71488: league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 u…nvd · 2026-08-06
- mediumCVE-2026-71478: league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 u…nvd · 2026-08-06
- unknownCVE-2026-67434: PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standard…nvd · 2026-08-06
- highGHSA-hmqg-cxww-wqhq: PHP_CodeSniffer gitblame report command injection via crafted filenameghsa · 2026-08-06
- criticalCVE-2026-65581: Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.nvd · 2026-08-06
More from CERT-FR Avis de sécurité
- unknownVulnerability in Sonicwall SonicOS (August 6, 2026)2026-08-06
- unknownMultiple vulnerabilities in Wallix products (August 6, 2026)2026-08-06
- unknownMultiple vulnerabilities in Cisco products (August 6, 2026)2026-08-06
- unknownMultiple vulnerabilities in Nextcloud products (August 6, 2026)2026-08-06
- unknownMultiple vulnerabilities in KeyCloak (August 6, 2026)2026-08-06