# CERT-FR warns of multiple PHP vulnerabilities

Published: 2026-07-31 · Severity: medium
Canonical: https://vorant.io/reports/e8d11871-df98-5aa3-bbe6-304c082d1e72/cert-fr-warns-of-multiple-php-vulnerabilities

> CERT-FR advises patching PHP 8.2-8.5 branches to fix flaws enabling SQL injection and denial of service.

CERT-FR issued an advisory covering multiple vulnerabilities in PHP affecting versions 8.2.x prior to 8.2.33, 8.3.x prior to 8.3.33, 8.4.x prior to 8.4.24, and 8.5.x prior to 8.5.9. The flaws, tracked under four CVE identifiers, allow attackers to trigger SQL injection, denial of service, and an unspecified security issue as described by the vendor.

The PHP project released patched versions (8.2.33, 8.3.33, 8.4.24, and 8.5.9) on July 30, 2026, addressing these issues. There is no indication in the advisory of active exploitation in the wild; organizations running affected PHP versions are advised to upgrade to the fixed releases referenced in the official PHP changelogs.

## Mentioned in this report

- Vulnerabilities: CVE-2026-17543, CVE-2026-17544, CVE-2026-7260, CVE-2026-9672

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0952

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/e8d11871-df98-5aa3-bbe6-304c082d1e72/cert-fr-warns-of-multiple-php-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
