Linuxsecurity Critical XSS and Memory Vulnerabilities in Oracle PHP Releases
Article Content
- •Critical XSS vulnerability (CVE-2026-6735) fixed in Oracle PHP updates.
- •Multiple memory management issues addressed in PHP versions 7.4 and 8.0.
- •Patches available for Oracle Linux 8 and 9; immediate application recommended.
Oracle has released important security updates for PHP versions 7.4 and 8.0, addressing multiple vulnerabilities including critical cross-site scripting (XSS) flaws and memory management issues. The updates fix CVE-2026-6735, which allows XSS attacks through the status endpoint, and CVE-2026-7259, which involves a null pointer dereference in the mb_check_encoding function. Other vulnerabilities include CVE-2026-6722, CVE-2026-7261, CVE-2026-7262, CVE-2026-7568, and CVE-2026-7258, all published on 2026-05-10. Affected systems include Oracle Linux 8 and 9, with specific updates for PHP 7.4 and 8.0. Users are urged to apply these patches immediately to mitigate potential exploitation risks. The vulnerabilities could lead to unauthorized access and data breaches if left unaddressed.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-6722 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Twitch Chat Messages Exploit OBS Studio via Chromium Vulnerability A vulnerability in OBS Studio allows malicious Twitch chat messages to execute native code on streamers' Windows PCs. This exploit targets users running OBS Studio version 32.2.2 or older, leveraging a cross-site scripting (XSS) flaw in custom overlays that render viewer messages as unsanitized HTML. The attack…