PHP disclosed fixes for two high-severity vulnerabilities affecting multiple supported branches. CVE-2026-17543 is an SQL injection flaw in ext-pgsql caused by improper escaping of backslashes in attacker-controlled parameters, enabling trivial injection through E'...' breakout. CVE-2026-17544 is an out-of-bounds write in ext-bcmath where crafted input to bccomp() can trigger stack and heap corruption. Both issues are rated as network-exploitable with low attack complexity and high impact on confidentiality, integrity, and availability, and CISA SSVC metadata indicates no exploitation has been observed but both flaws are considered automatable with total technical impact.
The vulnerabilities affect PHP versions before 8.2.33, 8.3.33, 8.4.24, and 8.5.9, with the bccomp() flaw applying to 8.4.x and 8.5.x before those patched releases. The Canadian Centre for Cyber Security published advisory AV26-764, echoing the PHP Group notice and urging users and administrators to review the vendor guidance and update affected deployments as fixes become available.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On July 30, 2026, PHP announced four security releases: versions 8.5.9, 8.4.24, 8.3.33, and 8.2.33. The releases fixed multiple issues including CVE-2026-17543, CVE-2026-17544, CVE-2026-7260, and CVE-2026-9672.
On July 30, 2026, the Canadian Centre for Cyber Security published advisory AV26-764 warning that multiple PHP branches prior to 8.2.33, 8.3.33, 8.4.24, and 8.5.9 are affected by the ext-pgsql SQL injection flaw and the bccomp() out-of-bounds write. The advisory urged users and administrators to review the referenced links and apply updates as they become available.
A vulnerability in PHP's ext-bcmath package was disclosed in which attacker-controlled input to bccomp() can trigger an out-of-bounds write leading to stack and heap corruption. The issue affects PHP 8.4.x before 8.4.24 and 8.5.x before 8.5.9.
A SQL injection flaw in PHP's ext-pgsql package was disclosed, caused by improper escaping of backslashes in attacker-provided parameters that can enable trivial SQL injection. Affected versions include PHP 8.2.x before 8.2.33, 8.3.x before 8.3.33, 8.4.x before 8.4.24, and 8.5.x before 8.5.9.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceseclists.org
Open sourcemalware.news
Open sourcecyber.gc.ca
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.