CVE-2026-34084Disclosure(phpoffice / phpspreadsheet)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch phpoffice phpspreadsheet systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and 4.0.0 through 5.5.0, when the filename argument to IOFactory::load() is user-controlled, an attacker can supply a PHP stream wrapper path (such as phar://, ftp://, or ssh2.sftp://) that passes the is_file() check in File::assertFile(). The phar:// wrapper triggers deserialization of the PHAR metadata, which can lead to remote code execution if a suitable gadget chain is available in the application. The ftp:// and ssh2.sftp:// wrappers can be used for server-side request forgery. This issue has been fixed in versions 1.30.3, 2.1.15, 2.4.4, 3.10.4, and 5.6.0.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • phpspreadsheet

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 3 mentions (2026-05-05); latest day: 1
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
phpspreadsheet

Deep dive

Activity timeline8 mentions / 5d
01223Mentions · 2026-05-05: 3Mentions · 2026-05-12: 2Mentions · 2026-06-09: 1Mentions · 2026-06-11: 1Mentions · 2026-06-12: 1PoC Mentioned / Linked · 2026-06-11: 1PoC Mentioned / Linked · 2026-06-12: 1Patch / Workaround · 2026-06-11: 1Patch / Workaround · 2026-06-12: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-12: 1Technical Details · 2026-06-09: 1Technical Details · 2026-06-12: 105-0505-1206-0906-1106-12
Signal classification3 categories
Disclosure
450.0%
General
225.0%
Patch
225.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-05-053
Disclosure3
2026-05-122
General2
2026-06-091
Disclosure1
2026-06-111
Patch1
2026-06-121
Patch1
Full discourse8 posts
  • Orca Security@orcasec
    Patch

    🚨 CRITICAL: PhpSpreadsheet CVE-2026-45034 (CVSS 9.8) The previous patch for CVE-2026-34084 was bypassed. Attackers can achieve full RCE with no authentication, and a public PoC is already out. Patch to 1.30.5 now 👇 https://orca.security/resources/blog/cve-2026-45034-phpspreadsheet-rce-patch-bypass/?utm_source=twitter&utm_medium=organic+social&utm_campaign=orca+blog https://t.co/rmsEllLNnc

    Post summary

    A critical RCE vulnerability (CVE-2026-45034) in PhpSpreadsheet is highlighted, noting that a previous patch was bypassed, a public PoC exists, and a patch to 1.30.5 is now available to mitigate the issue.

    00070630
    4.8K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CRITICAL: CVE-2026-34084 (CVSS 9.8) — phpoffice phpspreadsheet

    Post summary

    The post merely lists CVE‑2026‑34084 with a CVSS score of 9.8, without any exploitation, remediation, or detailed vulnerability description.

    1000029
    210 followersView on X
  • USHIDO Hiroyuki / kes@iso2022jp
    Patch

    PHPSpreadsheet has a patch bypass for CVE-2026-34084 https://github.com/advisories/GHSA-87m4-826x-3crx

    Post summary

    The post notes that PHPSpreadsheet has a patch bypass for CVE-2026-34084, with a link to a GitHub advisory for further context.

    0000065
    291 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 PhpSpreadsheet, Phar Wrapper Bypass, #CVE-2026-34084 (Critical) -DC-Jun2026-303 https://dailycve.com/phpspreadsheet-phar-wrapper-bypass-cve-2026-34084-critical-dc-jun2026-303/

    Post summary

    The post announces a critical CVE-2026-34084 affecting PhpSpreadsheet via a Phar wrapper bypass, linking to a dailycve.com article for further details, but does not provide PoC, exploit code, or reports of active exploitation.

    0000039
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-34084-phpoffice-phpspreadsheet #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The text references a CVE via a URL but lacks detailed information or actionable intelligence.

    0000021
    210 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-34084 Remote Code Execution via PHP Stream Wrapper in PhpSpreadsheet Multiple Versions https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-34084

    Post summary

    The text announces a new RCE vulnerability in PhpSpreadsheet via PHP stream wrapper, providing a high-level technical detail but no PoC, exploit, or patch information.

    0000050
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-34084 PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3… https://www.cve.org/CVERecord?id=CVE-2026-34084 ----- Traducción: CVE-2026-34084 Php… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑34084 affecting specific versions of PhpSpreadsheet and links to the CVE record, but provides no technical, exploit, or mitigation details.

    0000036
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34084 PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3… https://www.cve.org/CVERecord?id=CVE-2026-34084

    Post summary

    The statement reports CVE‑2026‑34084 impacting specific PhpSpreadsheet releases but offers no PoC, exploit, active threat, patch, or technical detail beyond version ranges.

    00000148
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appphpofficephpspreadsheet---

Explore more