CVE-2026-17543 (matched: php)

  • Friday, 7th August, 2026
  • 16:06pm

A security flaw has been identified in specific versions of PHP, the software that powers most dynamic websites including content management systems, online stores, and custom web applications. The issue is caused by incorrect handling of backslash characters in data submitted by visitors to your site. This flaw makes a common type of cyberattack called SQL injection extremely easy for bad actors to carry out. If exploited, attackers could access, modify, or delete information stored in your website's database, such as customer details, order records, login credentials, or public site content. The vulnerability impacts all PHP versions in the 8.2 release line older than 8.2.33, the 8.3 release line older than 8.3.33, the 8.4 release line older than 8.4.24, and the 8.5 release line older than 8.5.9. Newer patch versions for each of these release lines are not affected.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-17543

« Back