CVE-2026-12184Patch

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 4 observed days
  • Momentum state: declining

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 9 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 6 mentions (2026-07-06); latest day: 1
  • 9 total mentions across 4 days

Deep dive

Activity timeline9 mentions / 4d
02356Mentions · 2026-07-06: 6Mentions · 2026-07-08: 1Mentions · 2026-07-13: 1Mentions · 2026-08-02: 1Patch / Workaround · 2026-07-06: 4Patch / Workaround · 2026-07-08: 1Technical Details · 2026-07-06: 6Technical Details · 2026-07-08: 1Technical Details · 2026-07-13: 1Technical Details · 2026-08-02: 107-0607-0807-1308-02
Signal classification3 categories
Patch
555.6%
Disclosure
333.3%
General
111.1%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-07-066
Disclosure2Patch4
2026-07-081
Patch1
2026-07-131
Disclosure1
2026-08-021
General1
Full discourse9 posts
  • Netlas.io@Netlas_io
    Disclosure

    CVE-2026-12184: Remote DoS in PHP, 8.2 rating 🔥 Failure to setup TLS handshake with a remote server can lead to DoS. 👉 https://nt.ls/pjJC5

    Post summary

    The post announces CVE-2026-12184, a Remote DoS vulnerability in PHP related to TLS handshake failures, rating 8.2.

    0201211.2K
    7.7K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    Two PHP flaws are patched. CVE-2026-12184 is a PHP remote DoS that crashes PHP-FPM, and CVE-2026-14355 causes memory corruption. Update PHP now. #PHP #RemoteDoS #DoS #PHPFPM #CyberSecurity #Vulnerability #InfoSec http://securityonline.info/php-remote-dos-cve-2026-12184/

    Post summary

    The post announces that two PHP CVEs (CVE‑2026‑12184 and CVE‑2026‑14355) have been fixed and urges users to update PHP to mitigate the remote DoS and memory corruption vulnerabilities.

    02142847
    12.9K followersView on X
  • Tre B@trerbbb
    General

    github CVE-2026-12184: DoS. another reminder that your perimeter list is never as short as you think it is. #GitHub #DoS #CVE-2026-12184 https://valtikstudios.com

    Post summary

    The post merely announces CVE-2026-12184 as a DoS vulnerability with no further exploitation, patch, or PoC details.

    0101060
    17 followersView on X
  • Cyber Edition@CyberEdition
    Patch

    🐞 A newly disclosed PHP flaw (CVE-2026-12184) can let attackers trigger remote DoS attacks by crashing PHP-FPM workers through TLS error handling. Update to the latest patched PHP release as soon as possible. #CyberSecurity #PHP Read more: https://thecyberedition.com/php-cve-2026-12184-flaw-enables-remote-dos-attacks-on-php-fpm/

    Post summary

    The post announces a PHP flaw (CVE‑2026‑12184) that forces PHP‑FPM workers to crash via TLS errors, and urges immediate update to the patched PHP release.

    00011107
    739 followersView on X
  • くろん|情シスAIラボ@josys_AI_labo
    Patch

    PHP-FPM使ってHTTPS公開してる環境、今すぐ確認を。 CVE-2026-12184、CVSS v4.0スコア8.2のHigh。 TLS接続エラーの処理不備で PHP-FPMプロセスが丸ごと止まる可能性がある。 対象は PHP 8.3.32未満 PHP 8.4.21未満 PHP 8.5.6未満 修正版にアップデートするだけ。 でも「本番に当てる前に検証環境で」ってなって そのまま週をまたぐやつ、あるよな。 外部APIとHTTPS連携してる部分が止まると 障害切り分けに時間を食うので早めに。

    Post summary

    CVE‑2026‑12184 is a high‑severity TLS processing bug that can crash PHP‑FPM; update to the fixed version as soon as possible.

    1000060
    21 followersView on X
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Patch

    New PHP TLS flaw (CVE-2026-12184) enables remote DoS, crashing web apps. Impacts data availability & integrity in transit. Patch immediately. (Jul 6, 2026) #Cybersecurity #Vulnerability #News

    Post summary

    The tweet announces a PHP TLS remote DoS flaw (CVE-2026-12184) and urges immediate patching.

    0000152
    14 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    PHP の深刻な脆弱性 CVE-2026-12184 が FIX:TLS の欠陥と PHP-FPM クラッシュの恐れ https://iototsecnews.jp/2026/07/06/php-tls-flaw-lets-remote-server-trigger-dos-and-crash-entire-fpm-process/ PHP の深刻な脆弱性である CVE-2026-12184 について紹介する記事です。 この問題の主な原因は、 アウトバウンド接続時に TLS の初期化が失敗した際のエラー処理のロジックの不備にあります。メモリ解放後に不適切な処理が行われてしまうため、 外部のサーバと通信するだけでプロセスがクラッシュし、 サービス停止を引き起こすリスクがあります。 公式の回避策はないため、修正バージョンへの速やかなアップデートが必須となります。ご利用のチームは、十分に ご注意ください。 #CVE202612184 #PHP #Vulnerability

    Post summary

    The article discloses CVE-2026-12184 as a TLS initialization flaw that can crash PHP‑FPM, urging an update, but provides no PoC, exploit, or patch details.

    00000160
    500 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Disclosure

    🚨 PHP TLS Handshake Flaw Exposes Millions of Web Servers to Remote Crash Attacks — #CVE-2026-12184 Deep Dive + Video https://undercodetesting.com/php-tls-handshake-flaw-exposes-millions-of-web-servers-to-remote-crash-attacks-cve-2026-12184-deep-dive-video/ Educational Purposes!

    Post summary

    The text alerts readers to the PHP TLS handshake vulnerability (CVE‑2026‑12184) that could allow remote crash attacks on millions of web servers, but it provides no evidence of exploitation, PoC, or mitigation.

    0000058
    650 followersView on X
  • TECHEPAGES@techepages
    Patch

    PHP patches remote DoS and OpenSSL memory corruption flaws - Fixes are out across supported branches for a high-severity TLS stream bug and a moderate heap corruption issue. 💥 CVE-2026-12184 (High, 8.7): A failed TLS handshake, even just an expired certificate on a remote server crashes the entire PHP-FPM process and all workers; fixed in 8.3.32, 8.4.21, 8.5.6. 🔐 CVE-2026-14355 (Moderate, 4.7): Undersized buffers in openssl_encrypt() with AES-WRAP-PAD corrupt heap metadata, surfacing later as hard-to-diagnose allocator aborts; fixed in 8.2.32, 8.3.32, 8.4.23, 8.5.8.

    Post summary

    PHP has issued fixes for two CVEs—one high‑severity TLS handshake crash and one moderate OpenSSL buffer overrun—providing detailed version upgrade paths.

    0000061
    23 followersView on X

Explore more