SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-17544

CRITICAL · CVSS 9.8 EPSS 0.43% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The vulnerability in PHP affects the bccomp() function, where attacker-controlled inputs can result in an out-of-bounds write, potentially leading to stack and heap corruption. This could allow an attacker to execute arbitrary code or crash the application. Developers and system administrators using PHP versions 8.4.* prior to 8.4.24 and 8.5.* prior to 8.5.9 should prioritize applying the necessary updates to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-17544
Severity
CRITICAL
CVSS
9.8
EPSS
0.43%

Original NVD Description

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

Related CVEs

Other vulnerabilities affecting the same vendor(s)