CVE-2026-6735Patch(php / php)

LOWCVSS 6.1 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch php php systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • php

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 4 mentions (2026-05-12); latest day: 4
  • 10 total mentions across 3 days

Affected systems

Vendors
Products
php

Deep dive

Activity timeline10 mentions / 3d
01234Mentions · 2026-05-10: 2Mentions · 2026-05-12: 4Mentions · 2026-05-13: 4Patch / Workaround · 2026-05-12: 4Patch / Workaround · 2026-05-13: 4Technical Details · 2026-05-10: 2Technical Details · 2026-05-13: 105-1005-1205-13
Signal classification2 categories
Patch
880.0%
Disclosure
220.0%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-05-102
Disclosure2
2026-05-124
Patch4
2026-05-134
Patch4
Full discourse10 posts
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php83 Module Update 8.3.31-1 https://kusanagi.tokyo/en/releases/24567/ KUSANAGI 9 modules have been updated. The updated modules are as follows: php 8.3.31-1 This update includes support for vulnerability(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261,...

    Post summary

    KUSANAGI 9 php83 module update 8.3.31-1 addresses several CVEs by providing patches, but the release notes contain no PoC, exploit details, or evidence of ongoing attacks.

    010101.1K
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php83 モジュール更新情報 8.3.31-1 https://kusanagi.tokyo/releases/24566/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 php 8.3.31-1 この更新には脆弱性(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261, CVE-2026-7262, CVE-2026-7568, CVE-2...

    Post summary

    Kusanagi released php83 module update 8.3.31‑1 that mitigates several CVEs, with no exploitation or PoC details provided.

    01010104
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php83 モジュール更新情報 8.3.31-1.el9 https://kusanagi.tokyo/releases/24559/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 php 8.3.31-1.el9 この更新には脆弱性(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261, CVE-2026-7262, CVE-2026-756...

    Post summary

    The announcement details a module update that patches multiple CVEs, providing a mitigation for the reported vulnerabilities.

    0101099
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php82 モジュール更新情報 8.2.31-1.el9 https://kusanagi.tokyo/releases/24522/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 php 8.2.31-1.el9 この更新には脆弱性(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261, CVE-2026-7262, CVE-2026-756...

    Post summary

    The update announces patches for multiple CVEs affecting the KUSANAGI 9 modules.

    0101094
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php83 Module Update 8.3.31-1.el9 https://kusanagi.tokyo/en/releases/24560/ KUSANAGI 9 modules have been updated. The updated modules are as follows: php 8.3.31-1.el9 This update includes support for vulnerability(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722,...

    Post summary

    A module update for KUSANAGI 9 includes fixes for multiple CVEs, providing a patch for the listed vulnerabilities.

    000001.0K
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php82 Module Update 8.2.31-1 https://kusanagi.tokyo/en/releases/24534/ KUSANAGI 9 modules have been updated. The updated modules are as follows: php 8.2.31-1 This update includes support for vulnerability(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261,...

    Post summary

    The post announces a modules update that patches several CVEs, but provides no additional technical details or exploit information.

    00000787
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php82 モジュール更新情報 8.2.31-1 https://kusanagi.tokyo/releases/24533/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 php 8.2.31-1 この更新には脆弱性(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261, CVE-2026-7262, CVE-2026-7568, CVE-2...

    Post summary

    Kusanagi is releasing a PHP 8.2.31‑1 update that includes fixes for several CVEs, providing a patch for the identified vulnerabilities.

    0000070
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php82 Module Update 8.2.31-1.el9 https://kusanagi.tokyo/en/releases/24523/ KUSANAGI 9 modules have been updated. The updated modules are as follows: php 8.2.31-1.el9 This update includes support for vulnerability(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722,...

    Post summary

    Kusanagi PHP modules updated to address multiple CVEs; a patch is available via the provided release link.

    00000753
    200 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6735 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to com… https://www.cve.org/CVERecord?id=CVE-2026-6735

    Post summary

    The snippet announces a newly disclosed vulnerability (CVE-2026‑6735) impacting multiple PHP releases due to inadequate input sanitization.

    00000135
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6735 Cross-Site Scripting in PHP-FPM Status Page Multiple Versions Before 8.2.... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6735 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    A cross‑site scripting vulnerability in PHP‑FPM status pages pre‑8.2 has been disclosed, with further details accessible via the provided Vulmon links.

    0000055
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appphpphp---

Explore more