Frequency
6
occurrences
First Seen
April 14, 2026
Last Seen
August 10, 2026
Related Threat Clusters
-
Critical Command Injection Vulnerabilities in Composer's Perforce Driver
Two command injection vulnerabilities, CVE-2026-40176 and CVE-2026-40261, have been identified in Composer's Perforce VCS driver, allowing attackers to execute arbitrary commands on user systems. CVE-2026-40176,…
5 articles · Updated April 15, 2026 -
Critical PHP Composer Vulnerabilities Allow Remote Command Execution
Two high-severity vulnerabilities in PHP Composer, a dependency manager for PHP, have been identified, allowing attackers to execute arbitrary commands. These flaws can be exploited through malicious repository…
3 articles · Updated April 15, 2026 -
GitHub Expands Dependabot Malware Alerts to Eight Ecosystems
GitHub has expanded its Dependabot malware alerts to include eight ecosystems: npm, PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer. This change, effective August 2026, allows for automatic ingestion of…
4 articles · Updated August 10, 2026
Recent Intelligence Reports
- GitHub Expands Dependabot Malware Alerts to Detect Malicious Packages Across 8 Ecosystems — Gbhackers · August 10, 2026
- GitHub Dependabot malware alerts now cover eight ecosystems — Feeds2.Feedburner · August 10, 2026
- PHP Composer vulnerabilities allow arbitrary command execution | brief — Scworld · April 16, 2026
- New PHP Composer Vulnerability Let Attackers Execute Arbitrary Commands — Cybersecuritynews · April 15, 2026
- PHP Composer flaws enable remote command execution via Perforce VCS — Securityaffairs.Co · April 15, 2026
- New PHP Composer Flaws Enable Arbitrary Command Execution — Thehackernews · April 14, 2026