In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in ...
Continue reading
A security flaw has been identified in specific versions of the PHP programming language that powers many websites. The affected versions are PHP 8.2 releases older than 8.2.31, 8.3 releases older than 8.3.31, 8.4 releases older than 8.4.21, and 8.5 releases older than 8.5.6.The bug exists in the part of PHP used to connect to Firebird databases. ...
Continue reading
PhpSpreadsheet is a widely used software library that helps websites read, write, and edit spreadsheet files like Excel and CSV. A security vulnerability exists in multiple older versions of this library, but only impacts sites that let visitor input control which spreadsheet file the library loads.
Attackers can exploit this flaw in two main ...
Continue reading
On 20 July 2026, cybersecurity agency MyCERT released an advisory focused on securing Microsoft SharePoint, a common platform businesses use to store, share and collaborate on documents and team content. The advisory was issued after new exploitation methods targeting SharePoint installations were recently observed.These newly identified ...
Continue reading