{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/php-8.2.x--8.2.34-8.3.x--8.3.35-8.4.x--8.4.26-8.5.x--8.5.11/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PHP (8.2.x \u003c 8.2.34, 8.3.x \u003c 8.3.35, 8.4.x \u003c 8.4.26, 8.5.x \u003c 8.5.11)"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","web-application","patch-management"],"_cs_type":"advisory","_cs_vendors":["PHP"],"content_html":"\u003cp\u003eThe PHP Group has released security updates addressing multiple vulnerabilities across several active PHP release branches. These vulnerabilities, identified as CVE-2025-1218, CVE-2025-14181, CVE-2026-17545, CVE-2026-6103, CVE-2026-91765, CVE-2026-91766, CVE-2026-91767, CVE-2026-91768, CVE-2026-91769, CVE-2026-92842, and CVE-2026-93682, impact versions of PHP 8.2.x, 8.3.x, 8.4.x, and 8.5.x. Depending on the specific flaw, exploitation may lead to remote denial-of-service (DoS) conditions, unauthorized disclosure of sensitive information, or the modification of application data. These issues represent a significant risk for any organization hosting PHP-based web applications, as the runtime environment is a core component of many enterprise web stacks. Defenders must prioritize upgrading to the patched versions: 8.2.34, 8.3.35, 8.4.26, and 8.5.11 to remediate these security gaps.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities can lead to service outages, exposure of proprietary or PII data, and unauthorized alteration of application state. Given the ubiquitous nature of PHP in web server environments, these flaws affect a broad range of sectors including e-commerce, content management systems, and custom internal web applications. Failure to patch may allow unauthenticated or remote attackers to disrupt business operations or gain deeper insight into sensitive back-end infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for detection and remediation teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all PHP instances to the following patched versions immediately: 8.2.34, 8.3.35, 8.4.26, or 8.5.11.\u003c/li\u003e\n\u003cli\u003eReview web server logs for irregular traffic patterns or excessive error spikes that may indicate exploitation attempts against the PHP engine.\u003c/li\u003e\n\u003cli\u003ePatch CVE-2025-1218, CVE-2025-14181, CVE-2026-17545, CVE-2026-6103, CVE-2026-91765, CVE-2026-91766, CVE-2026-91767, CVE-2026-91768, CVE-2026-91769, CVE-2026-92842, and CVE-2026-93682 by applying the latest vendor updates.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-24T13:57:31Z","date_published":"2026-09-24T13:57:31Z","id":"https://feed.craftedsignal.io/briefs/2026-09-php-vulnerabilities/","summary":"Multiple vulnerabilities across several PHP versions allow remote attackers to cause denial-of-service, access sensitive data, and compromise data integrity.","title":"Multiple Vulnerabilities in PHP Runtime Environment","url":"https://feed.craftedsignal.io/briefs/2026-09-php-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - PHP (8.2.x \u003c 8.2.34, 8.3.x \u003c 8.3.35, 8.4.x \u003c 8.4.26, 8.5.x \u003c 8.5.11)","version":"https://jsonfeed.org/version/1.1"}