Skip to content
Moderate Stack Overflow Vulnerability in php7 Affects SUSE and openSUSE

Moderate Stack Overflow Vulnerability in php7 Affects SUSE and openSUSE

First seen 12 Sep 2026, 07:27 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 12, 2026 at 10:52 UTC
  • CVE-2026-7260 is a moderate stack overflow vulnerability in php7.
  • Affected systems include SUSE Linux Enterprise and openSUSE distributions.
  • Patches were released on September 11, 2026, following the CVE publication on July 30, 2026.

A moderate stack overflow vulnerability, identified as CVE-2026-7260, has been reported in php7, specifically affecting systems with circular symlinks in phar files. This vulnerability allows for potential exploitation, impacting SUSE Linux Enterprise Server and openSUSE users. The vulnerability has a CVSS score of 4.0, indicating a moderate severity level. Users are advised to apply patches immediately to mitigate risks. The vulnerability was published on July 30, 2026, and has been addressed in updates released on September 11, 2026. Additional changes in the patch allow for the removal of apache2-mod_php7 even if the module is not enabled. Administrators are encouraged to follow SUSE's recommended installation methods for applying the updates. The updates are available for various SUSE products including SAP Applications and High Performance Computing versions.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-07-30
CVE-2026-7260 published
A stack overflow vulnerability in php7 was disclosed, affecting systems with circular symlinks in phar files.
Linuxsecurity
2026-09-11
Patch released for php7
SUSE and openSUSE released updates addressing CVE-2026-7260, urging users to apply them immediately.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track CVE-2026-7260 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed