Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
Recent updates for openSUSE PHP versions 7 and 8 have revealed critical vulnerabilities, including SQL injection and C stack exhaustion issues. Specifically, CVE-2026-17543 allows for SQL injection through improper escaping of user-provided parameters in `ext-pgsql`, while CVE-2026-7260 can lead to...
Oracle has issued important bug fix advisories for PHP vulnerabilities affecting Oracle Linux 8 and 9. The vulnerabilities include CVE-2026-17543, a SQL injection flaw, and CVE-2026-7260, which can cause crashes via recursive symlinks. These vulnerabilities impact PHP versions 7.4 and 8.2, respectiv...
Recent vulnerabilities in PHP could allow remote attackers to cause denial of service on affected systems. Specifically, issues were identified in PHP 7.0, including improper handling of Apache map decoding (CVE-2026-7262), signed integer overflow in the metaphone() function (CVE-2026-7568), and cir...
A moderate stack overflow vulnerability, identified as CVE-2026-7260, has been reported in php7, specifically affecting systems with circular symlinks in phar files. This vulnerability allows for potential exploitation, impacting SUSE Linux Enterprise Server and openSUSE users. The vulnerability has...