PHP Multiple Vulnerabilities
CSIRTS triage
- What
- PHP contains multiple unspecified vulnerabilities.
- Who is affected
- All PHP installations with affected versions are at risk.
- Urgency
- Urgent; multiple vulnerability classes require immediate assessment and patching.
- Action
- Upgrade to the latest patched PHP version and review CVE details for each identifier.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch PHP
Get an email when a new PHP advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.hkcert.org/security-bulletin/php-multiple-vulnerabilities_20260803
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-72600.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-175430.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-175440.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-7260 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9672 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-17543 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-17544 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [hoch] PHP: Mehrere Schwachstellencert-bund
- unknownUSN-8743-1: PHP vulnerabilitiesubuntu
- unknownUSN-8734-1: PHP vulnerabilitiesubuntu
- unknownDSA-6409-1 libgd2 - security updatedebian
- unknownMultiple vulnerabilities in PHP (July 31, 2026)cert-fr-avis
- unknownDSA-6406-1 php8.4 - security updatedebian
- mediumCVE-2026-7260: Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C st…nvd
- criticalCVE-2026-17544: Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap …nvd
- criticalCVE-2026-17543: Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL i…nvd
- mediumCVE-2026-7260: Stack overflow in phar with circular symlinksmsrc
- criticalCVE-2026-17543: SQL injection in ext-pgsql via E'...' backslash breakoutmsrc
More from HKCERT Security Bulletins
- unknownPalo Alto Products Multiple Vulnerabilities2026-09-10
- unknownMongoDB Multiple Vulnerabilities2026-09-10
- unknownGoogle Chrome Multiple Vulnerabilities2026-09-10
- unknownCitrix Products Multiple Vulnerabilities2026-09-10
- unknownAdobe Monthly Security Update (September 2026)2026-09-09