<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>PHP (8.2.x &lt; 8.2.34, 8.3.x &lt; 8.3.35, 8.4.x &lt; 8.4.26, 8.5.x &lt; 8.5.11) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/php-8.2.x--8.2.34-8.3.x--8.3.35-8.4.x--8.4.26-8.5.x--8.5.11/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 24 Sep 2026 13:57:31 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/php-8.2.x--8.2.34-8.3.x--8.3.35-8.4.x--8.4.26-8.5.x--8.5.11/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Multiple Vulnerabilities in PHP Runtime Environment</title><link>https://feed.craftedsignal.io/briefs/2026-09-php-vulnerabilities/</link><pubDate>Thu, 24 Sep 2026 13:57:31 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-php-vulnerabilities/</guid><description>Multiple vulnerabilities across several PHP versions allow remote attackers to cause denial-of-service, access sensitive data, and compromise data integrity.</description><content:encoded><![CDATA[<p>The PHP Group has released security updates addressing multiple vulnerabilities across several active PHP release branches. These vulnerabilities, identified as CVE-2025-1218, CVE-2025-14181, CVE-2026-17545, CVE-2026-6103, CVE-2026-91765, CVE-2026-91766, CVE-2026-91767, CVE-2026-91768, CVE-2026-91769, CVE-2026-92842, and CVE-2026-93682, impact versions of PHP 8.2.x, 8.3.x, 8.4.x, and 8.5.x. Depending on the specific flaw, exploitation may lead to remote denial-of-service (DoS) conditions, unauthorized disclosure of sensitive information, or the modification of application data. These issues represent a significant risk for any organization hosting PHP-based web applications, as the runtime environment is a core component of many enterprise web stacks. Defenders must prioritize upgrading to the patched versions: 8.2.34, 8.3.35, 8.4.26, and 8.5.11 to remediate these security gaps.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities can lead to service outages, exposure of proprietary or PII data, and unauthorized alteration of application state. Given the ubiquitous nature of PHP in web server environments, these flaws affect a broad range of sectors including e-commerce, content management systems, and custom internal web applications. Failure to patch may allow unauthenticated or remote attackers to disrupt business operations or gain deeper insight into sensitive back-end infrastructure.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for detection and remediation teams:</p>
<ul>
<li>Upgrade all PHP instances to the following patched versions immediately: 8.2.34, 8.3.35, 8.4.26, or 8.5.11.</li>
<li>Review web server logs for irregular traffic patterns or excessive error spikes that may indicate exploitation attempts against the PHP engine.</li>
<li>Patch CVE-2025-1218, CVE-2025-14181, CVE-2026-17545, CVE-2026-6103, CVE-2026-91765, CVE-2026-91766, CVE-2026-91767, CVE-2026-91768, CVE-2026-91769, CVE-2026-92842, and CVE-2026-93682 by applying the latest vendor updates.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>vulnerability</category><category>web-application</category><category>patch-management</category></item></channel></rss>