Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
Oracle has released important security updates for PHP versions 7.4 and 8.0, addressing multiple vulnerabilities including critical cross-site scripting (XSS) flaws and memory management issues. The updates fix CVE-2026-6735, which allows XSS attacks through the status endpoint, and CVE-2026-7259, w...
Recent vulnerabilities in PHP could allow remote attackers to cause denial of service on affected systems. Specifically, issues were identified in PHP 7.0, including improper handling of Apache map decoding (CVE-2026-7262), signed integer overflow in the metaphone() function (CVE-2026-7568), and cir...
On May 10, 2026, two critical vulnerabilities were published affecting PHP 8.4.21, specifically CVE-2026-7262 and CVE-2026-7263. These vulnerabilities impact Fedora versions 42 and 43, which utilize PHP for web development. The issues include assertion failures and memory management errors that coul...