Exploitation timeline
Threadlinqs has recorded 14 PHP Group CVEs published between and . The busiest month was 2026-09 (11 new CVEs). None of them is listed in CISA KEV yet.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 14 of 14 tracked PHP Group CVEs.
- CVE-2026-17544high 8.1EPSS 0.4%
- CVE-2026-17543high 8.1EPSS 0.4%
- CVE-2026-7260medium 5.4EPSS 0.2%
- CVE-2026-91765high 7.5
- CVE-2026-17545medium 6.9
- CVE-2025-14181medium 6.5
- CVE-2026-91767medium 6.5
- CVE-2026-91768medium 6.5
- CVE-2026-91766medium 5.9
- CVE-2026-92842medium 5.9
- CVE-2026-93682medium 5.8
- CVE-2026-6103medium 4.3
- CVE-2026-91769medium 4.3
- CVE-2025-1218low 3.4
Products affected
Threadlinqs normalises CPE and CNA product records across all 14 CVEs; 1 distinct PHP Group product is affected. The most frequently affected:
- PHP 14 CVEs
Threat activity
6 tracked threat campaigns reference PHP Group products or exploit PHP Group CVEs:
- Multiple PHP Vulnerabilities Enable Denial of Service, TLS Verification Bypass, and Credential Leakage (CVE-2026-91765, CVE-2026-91768, CVE-2026-6103 and 8 Others) — GovCERT.HK A26-09-40MEDIUM
- Dissection of a PHP Backdoor Leveraging php-win.exe for Stealthy Windows PersistenceMEDIUM
- Multiple Vulnerabilities in PHP (GovCERT.HK A26-07-52): Phar Symlink DoS, Bundled-libgd GIF Memory Corruption, pgsql SQL Injection, and BCMath Out-of-Bounds Write (CVE-2026-7260, CVE-2026-9672, CVE-2026-17543, CVE-2026-17544)HIGH
- HollowByte: OpenSSL Pre-Authentication TLS DoS Flaw Bloats Server Memory With 11-Byte PayloadMEDIUM
- OpenSSL "HollowByte" TLS Handshake Memory-Amplification DoS (No CVE Assigned)MEDIUM
- APT35 (Charming Kitten) GCC Pre-Positioning Cyber Reconnaissance Campaign Enabling Kinetic TargetingCRITICAL
Threat actors targeting PHP Group
Named threat actors attributed to campaigns that involve PHP Group products or CVEs, with the number of linked campaigns:
How to prioritise PHP Group patching
This order follows the data Threadlinqs holds for PHP Group, not a generic severity checklist:
- No PHP Group CVE is in CISA KEV yet, so rank by exploit probability instead.
- Outside KEV, the highest EPSS scores are CVE-2026-17544 (0.4%), CVE-2026-17543 (0.4%), CVE-2026-7260 (0.2%).
- 0 CVEs score Critical and 3 High on CVSS v3 (maximum 8.1, average 6.1); sequence these after KEV and high-EPSS items.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.