USN-8734-1: PHP vulnerabilities
It was discovered that PHP incorrectly handled Apache map decoding in SOAP servers with a typemap configured. A remote attacker could use this issue to cause a NULL pointer dereference, resulting in a denial of service. (CVE-2026-7262) It was discovered that PHP incorrectly handled signed integer overflow in the metaphone() function. An attacker could use this issue to cause an out-of-bounds read, resulting in a denial of service. (CVE-2026-7568) It was discovered that PHP incorrectly handled circular symbolic links in phar archives. An attacker could use this issue to cause unbounded recursion, resulting in a denial of service. (CVE-2026-7260) It was discovered that PHP incorrectly escaped backslashes in the pgsql extension when standard_conforming_strings is enabled. An attacker could use this issue to perform SQL injection via a backslash breakout. (CVE-2026-17543)
Details
Original advisory: https://ubuntu.com/security/notices/USN-8734-1
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-72620.78% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 54% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-75680.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-72600.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-175430.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-7262 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-7568 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-7260 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-17543 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownUSN-8743-1: PHP vulnerabilitiesubuntu
- high[UPDATE] [hoch] PHP: Mehrere Schwachstellencert-bund
- unknownMultiple vulnerabilities in Tenable products (August 4, 2026)cert-fr-avis
- unknownPHP Multiple Vulnerabilitieshkcert
- unknownDSA-6406-1 php8.4 - security updatedebian
- unknownMultiple vulnerabilities in PHP (July 31, 2026)cert-fr-avis
- mediumCVE-2026-7260: Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C st…nvd
- criticalCVE-2026-17543: Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL i…nvd
- high[UPDATE] [high] PHP: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Tenable Security Center (July 21, 2026)cert-fr-avis
- mediumCVE-2026-7260: Stack overflow in phar with circular symlinksmsrc
- criticalCVE-2026-17543: SQL injection in ext-pgsql via E'...' backslash breakoutmsrc
More from Ubuntu Security Notices
- unknownUSN-8747-1: Beets vulnerability2026-09-10
- unknownUSN-8746-1: libEBML vulnerability2026-09-10
- unknownUSN-8745-1: KissFFT vulnerabilities2026-09-10
- unknownUSN-8748-1: Linux kernel (NVIDIA) vulnerabilities2026-09-10
- unknownUSN-8744-1: Python vulnerabilities2026-09-10