CVE-2026-17544 (matched: php)

  • Friday, 7th August, 2026
  • 22:04pm

A security vulnerability, tracked as CVE-2026-17544, has been identified in specific versions of PHP, the programming language that powers many dynamic websites. The affected versions are PHP 8.4 releases older than 8.4.24, and PHP 8.5 releases older than 8.5.9.

The flaw can be triggered when specially crafted input from a site visitor is passed to a PHP math function called bccomp(), which some website code uses to compare large numbers. If exploited, this can corrupt parts of the server’s memory, which may cause your site to stop working unexpectedly, or in worst-case scenarios, allow an attacker to access sensitive site or server data.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-17544

« Back