CVE-2026-17544 is an out-of-bounds write vulnerability in PHP's BCMath extension, affecting bccomp() in PHP 8.4.x before 8.4.24 and PHP 8.5.x before 8.5.9. The flaw resides in bc_str2num() handling of fractional numeric data. When fractional digits are truncated and trailing zeroes removed, the vulnerable logic reduces the allocation size without updating the endpoint pointer for copied fractional data. Subsequent copying can write beyond the allocated buffer, corrupting stack or heap memory.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a compact exploit repo containing one real exploit file, exploit.php, plus a README and .gitignore. The exploit is a standalone PHP proof-of-concept/operational exploit for CVE-2026-17544, described as an out-of-bounds zero-write in PHP's rewritten bcmath implementation (bc_str2num) affecting PHP 8.4.x and 8.5.x in the vulnerable ranges. It is not a scanner or detector; it performs active exploitation. Repository structure: README.md explains the vulnerability, threat model, affected versions, usage, and exploitation stages. exploit.php contains the full exploit logic for both CLI and web contexts. There are no auxiliary modules, no framework metadata, and no external dependencies beyond a vulnerable PHP runtime with bcmath enabled. Main exploit capability: the code turns a bcmath-triggered OOB zero-write into a refcount-desynchronization/use-after-free condition on a neighboring zend_string, then uses that to obtain a giant-string relative read/write primitive. From there it builds a fault-safe arbitrary read primitive, leaks a text pointer, scans memory downward page-by-page to find the ELF base of the mapped PHP binary, parses ELF program headers to locate the writable .data segment, scans .data for the shell_exec zend_function_entry, resolves the zif_shell_exec handler address at runtime, and finally constructs fake Zend class/function/hash-table structures in writable memory to invoke that handler through a forged method call. The result is memory-only command execution with returned output, explicitly intended to bypass disable_functions and open_basedir. Operational flow in exploit.php: it sprays strings, frees a hole, triggers bccomp() with a crafted numeric string to induce the OOB write, validates giant-string corruption, creates Probe objects to locate controllable object memory, rewires a property into a fake zend_reference for arbitrary reads, leaks handler/text/base/data addresses, finds shell_exec, builds fake zend_string/zend_function/bucket/class_entry structures inside a controlled buffer, corrupts an object's class pointer to the fake class, invokes a fake method name (pwn) with attacker-controlled command input, restores the original class pointer, and echoes the command output. Attack surface and delivery: the exploit supports local CLI execution (`php exploit.php "id; uname -a"`) and web-based post-exploitation by deploying the script as a PHP file and passing a cmd parameter via GET or POST. It does not target a remote network service directly by IP/domain; instead it assumes the attacker already has the ability to execute PHP code in the target environment. The README explicitly states this is a sandbox escape/post-exploitation primitive rather than input-only remote RCE. In a pure user-input-to-bcmath scenario, the claimed impact is denial of service rather than full code execution. Notable fingerprintable observables include the use of the cmd request parameter, CLI argument $argv[1], the vulnerable bccomp() trigger, the fake method name pwn, and the runtime search for shell_exec/zif_shell_exec inside the PHP process image. No hardcoded external C2, URLs, IPs, or domains are present. The exploit is self-contained and performs all resolution in-process at runtime.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A PHP arbitrary code execution vulnerability caused by an out-of-bounds write in bccomp().
A high-severity out-of-bounds write vulnerability in PHP's BCMath extension affecting bccomp(), caused by incorrect buffer/end-pointer handling in bc_str2num() after truncating fractional digits and trailing zeroes.
An out-of-bounds write vulnerability in PHP's ext-bcmath bccomp() function that can cause stack and heap corruption.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.