CVE-2026-17544PoC(php / php)

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch php php systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • php

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: rising

What's happening

  • Exploit tool or code specified in 5 signals
  • PoC mentioned or linked in 5 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 9 signals
  • Peaked 2d ago at 4 mentions (2026-08-14); latest day: 1
  • 9 total mentions across 5 days

Affected systems

Vendors
Products
php

Deep dive

Activity timeline9 mentions / 5d
01234Mentions · 2026-08-06: 1Mentions · 2026-08-07: 1Mentions · 2026-08-14: 4Mentions · 2026-08-15: 2Mentions · 2026-08-23: 1PoC Mentioned / Linked · 2026-08-14: 4PoC Mentioned / Linked · 2026-08-15: 1Exploit Tool / Code · 2026-08-14: 4Exploit Tool / Code · 2026-08-15: 1Patch / Workaround · 2026-08-06: 1Patch / Workaround · 2026-08-07: 1Patch / Workaround · 2026-08-15: 1Patch / Workaround · 2026-08-23: 1Technical Details · 2026-08-06: 1Technical Details · 2026-08-07: 1Technical Details · 2026-08-14: 4Technical Details · 2026-08-15: 2Technical Details · 2026-08-23: 108-0608-0708-1408-1508-23
Signal classification2 categories
PoC
555.6%
Patch
444.4%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-061
Patch1
2026-08-071
Patch1
2026-08-144
PoC4
2026-08-152
Patch1PoC1
2026-08-231
Patch1
Full discourse9 posts
  • ThreatWire@ThreatWire_
    PoC

    🚨 PoC RELEASED: Public exploit code is available for CVE-2026-17544, a high-severity PHP memory corruption flaw in bccomp(). Attacker-controlled input can trigger an out-of-bounds write, potentially corrupting stack or heap memory. Affects PHP 8.4.x < 8.4.24 and 8.5.x < 8.5.9. 🔗 https://github.com/boreas37/cve-2026-17544-poc #PHP #CVE #PoC #CyberSecurity #WebSecurity #Infosec

    Post summary

    Public PoC code released for CVE-2026-17544, a high‑severity PHP memory corruption vulnerability affecting PHP 8.4.x < 8.4.24 and 8.5.x < 8.5.9; no patch is mentioned and no active exploitation has been reported.

    018071283.8K
    1.5K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    🔴 PHP'de kritik CVE-2026-17544 açığı için public PoC yayınlandı. bccomp() fonksiyonundaki bu bellek bozulması (memory corruption) açığı, saldırganın kontrol ettiği girdilerle sınır dışı bellek yazımına (out-of-bounds write) neden olabiliyor ve stack veya heap belleğinin bozulmasına yol açabiliyor. Etkilenen sürümler: • PHP 8.4.x < 8.4.24 • PHP 8.5.x < 8.5.9 https://github.com/boreas37/cve-2026-17544-poc

    Post summary

    The post announces that a public PoC for CVE‑2026‑17544 has been published on GitHub, detailing a memory corruption flaw in PHP’s bccomp() with affected versions specified.

    011065204.7K
    2.3K followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-17544 Vendor: PHP Group Product: PHP Description: Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9. Link: https://github.com/boreas37/cve-2026-17544-poc #dbugs_vuln

    Post summary

    A PoC and exploit for CVE‑2026‑17544 has been released, demonstrating an out‑of‑bounds write in PHP’s bccomp() function; no active exploitation or patch information is provided.

    0802891.7K
    3.5K followersView on X
  • RootNik Labs@rootniklabs
    Patch

    🚨 HIGH SEVERITY ALERT | CVE-2026-17544 Critical PHP memory corruption (OOB write) may lead to DoS, crashes, possible RCE. Affects PHP &lt; 8.5.9/8.4.24/8.3.33/8.2.33. Patch immediately #CVE202617544 #PHP #CyberSecurity #VAPT #RootNikLabs https://t.co/nX0Um8YJba

    Post summary

    The tweet warns of a critical memory corruption flaw (CVE‑2026‑17544) in PHP and urges users to apply the patch immediately.

    0002098
    276 followersView on X
  • iototsecnews@iototsecnews
    Patch

    PHP の 3件の深刻な脆弱性が FIS:SQLi/メモリ破壊/サーバ・クラッシュの恐れ https://iototsecnews.jp/2026/07/31/php-patches-three-flaws-enabling-sql-injection-memory-corruption-and-server-crashes/ PHP のデータベース処理/数値計算/アーカイブ読み込み時の不備などによる、複数の脆弱性 CVE-2026-17543/CVE-2026-17544/CVE-2026-7260 が公表されました。これらの問題は、入力値のエスケープ処理/バッファ境界の不適切な管理/参照追跡の不足などに起因しています。悪用された場合には、データベースの不正操作/メモリ破損による障害/システムの強制停止などが引き起こされる恐れがあります。対応策として、修正が含まれる最新バージョンへの速やかな移行と処理対象データの検証が有効です。システムを安全に利用するためにも、環境のアップデートを実施することが推奨されます。 #CVE202617543 #CVE202617544 #CVE20267260 #Vulnerability

    Post summary

    Three newly reported PHP vulnerabilities (CVE-2026-17543, CVE-2026-17544, CVE-2026-7260) pose risks of SQL injection, memory corruption, and server crashes; users are urged to apply the latest patches immediately.

    01000205
    505 followersView on X
  • takenaka hiroya@Joe_Biden_ja
    Patch

    PHPのBCMath拡張 bccomp() に領域外書き込み。8.4.3RC1で入った回帰なので、8.2系と8.3系はそもそも対象外です。修正版は8.4.24と8.5.9。ext-bcmathを有効にしているかどうかが、そのまま影響の有無になります。 https://cve.autoarticles.net/cve/CVE-2026-17544

    Post summary

    PHP BCMath bccomp() suffers an out‑of‑bounds write introduced in 8.4.3RC1; patched in 8.4.24 and 8.5.9, with no mention of exploitation or PoC.

    0000047
    562 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨High - PHP ext-bcmath bccomp() Out-of-Bounds Write (CVE-2026-17544) Attacker-controlled operands passed into PHP's ext-bcmath bccomp() can trigger an out-of-bounds write during big-number comparison, corrupting stack/heap and potentially leading to RCE or process crash. Non-bcmath code paths are not impacted. 👉Affected: PHP ext-bcmath 8.4.* < 8.4.24, 8.5.* < 8.5.9 | Upgrade to 8.4.24 / 8.5.9

    Post summary

    The tweet details an out‑of‑bounds write vulnerability in PHP's bcmath bccomp() function (CVE‑2026‑17544) and recommends upgrading to the patched PHP 8.4.24 or 8.5.9 releases.

    0000096
    289 followersView on X
  • Beralock@Beralock
    PoC

    Public PoC Released | CVE-2026-17544 Critical PHP memory corruption vulnerability in bccomp(). Affected: • PHP 8.4.x &lt; 8.4.24 • PHP 8.5.x &lt; 8.5.9 🔗 PoC: https://github.com/boreas37/cve-2026-17544-poc Organization should patch and exposure assessment. Follow- @Beralock #ThreatIntelligence

    Post summary

    A public proof‑of‑concept has been released for CVE‑2026‑17544, a critical PHP memory‑corruption flaw in bccomp(), urging organizations to patch affected PHP 8.4 and 8.5 versions.

    00000122
    14 followersView on X
  • Mahmoud Jadaan@mjadaaan
    PoC

    CVE-2026-17544: Stack smashing PHP bcmath bccomp() Out-of-Bounds Write https://github.com/boreas37/cve-2026-17544-poc

    Post summary

    A GitHub repository containing a proof‑of‑concept for CVE‑2026‑17544, a stack‑smashing out‑of‑bounds write in PHP's bcmath bccomp, has been posted.

    0000061
    42 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appphpphp---

Explore more