The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Multiple security vulnerabilities have been discovered in the MongoDB driver for PHP, which could result in information disclosure, PHP objection injection or …
PHP version 8.5.11 (24 Sep 2026) BCMath: Fixed out-of-bounds read in bc_is_zero_for_scale() when scale exceeds n_scale. (Ilia Alshanetsky) Core:
PHP version 8.4.26 (24 Sep 2026) BCMath: Fixed out-of-bounds read in bc_is_zero_for_scale() when scale exceeds n_scale. (Ilia Alshanetsky) Core:
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language which could result in denial of service, information d…
New php packages are available for Slackware 15.0 and -current to fix security issues.
Several security issues were fixed in PHP.
Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analy…
Oracle Linux has released updates for PHP and related packages in version 8.3.33 and various PHP extensions to address security vulnerabilities linked to speci…
Oracle Linux has released security updates for several packages, including libzip and php, addressing vulnerabilities and updating to the latest versions for i…
Fedora has released an update for php-phpseclib3 to version 3.0.56, addressing vulnerabilities CVE-2026-40194 and CVE-2026-44167, and it can be installed via t…
The Fedora 43 update for php-phpseclib3 to version 3.0.56 fixes vulnerabilities CVE-2026-40194 and CVE-2026-44167, improving security for the PHP Secure Commun…
A critical update for PHP on Rocky Linux 8 addresses SQL injection and denial of service vulnerabilities while also including various bug fixes and enhancement…
A significant update for PHP and various modules in Rocky Linux 9 addresses critical vulnerabilities, including SQL injection and denial of service issues, enh…
Oracle Linux has released updates for PHP 8.4.24 addressing CVEs 2026-17543 and 2026-17544, with new RPMs for x86_64 and aarch64 architectures available via th…
Fedora 44 has released an update for php-phpseclib to version 2.0.55, addressing CVE-2026-44167, which involves a denial of service due to untrusted ASN.1 file…
Fedora has released an update for php-phpseclib to version 2.0.55, addressing CVE-2026-44167, a denial of service vulnerability related to untrusted ASN.1 file…
The security release of php-pear-PHP-CodeSniffer version 4.0.4 addresses vulnerabilities and improves error messages, tokenizer support for PHP 8.5, and overal…
An update for Mageia 10 fixes an import error that caused the php[8.4,8.5]-imap package to lack SSL support, which is now deprecated and should be replaced.
An update for PHP 8.2 in Rocky Linux 8 addresses low severity vulnerabilities, including a Denial of Service flaw, along with bug fixes and enhancements.
Rocky Linux 9 has received a low severity update for PHP 8.3, addressing a buffer allocation flaw and includes bug fixes and enhancements for various PHP modul…
A security update for PHP on Rocky Linux 10 addresses a denial of service vulnerability and includes bug fixes and enhancements, with detailed CVE information …
A security and enhancement update for PHP 8.2, addressing a denial of service vulnerability and various bug fixes, is now available for Rocky Linux 9 users.
A security update for PHP 7.4 has been released for Rocky Linux 8, addressing a denial of service vulnerability and including various bug fixes and enhancement…
Oracle Linux issued a security advisory with updated RPM packages for PHP and related modules, addressing various vulnerabilities and introducing version updat…