# PHP Group vulnerabilities & exploitation

> As of 2026-10-05, Threadlinqs tracks 14 PHP Group CVEs, 0 in the CISA Known Exploited Vulnerabilities catalog, linked to 6 tracked threat campaigns and 2 named threat actors.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 14 PHP Group CVEs published between 2026-07-15 and 2026-09-15. The busiest month was 2026-09 (11 new CVEs). None of them is listed in CISA KEV yet.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 14 of 14 tracked PHP Group CVEs.

- [CVE-2026-17544](https://intel.threadlinqs.com/cve/CVE-2026-17544) — HIGH 8.1 · EPSS 0.4% · 2026-07-30
- [CVE-2026-17543](https://intel.threadlinqs.com/cve/CVE-2026-17543) — HIGH 8.1 · EPSS 0.4% · 2026-07-30
- [CVE-2026-7260](https://intel.threadlinqs.com/cve/CVE-2026-7260) — MEDIUM 5.4 · EPSS 0.2% · 2026-07-30
- [CVE-2026-91765](https://intel.threadlinqs.com/cve/CVE-2026-91765) — HIGH 7.5 · 2026-09-25
- [CVE-2026-17545](https://intel.threadlinqs.com/cve/CVE-2026-17545) — MEDIUM 6.9 · 2026-09-25
- [CVE-2025-14181](https://intel.threadlinqs.com/cve/CVE-2025-14181) — MEDIUM 6.5 · 2026-09-25
- [CVE-2026-91767](https://intel.threadlinqs.com/cve/CVE-2026-91767) — MEDIUM 6.5 · 2026-09-25
- [CVE-2026-91768](https://intel.threadlinqs.com/cve/CVE-2026-91768) — MEDIUM 6.5 · 2026-09-25
- [CVE-2026-91766](https://intel.threadlinqs.com/cve/CVE-2026-91766) — MEDIUM 5.9 · 2026-09-25
- [CVE-2026-92842](https://intel.threadlinqs.com/cve/CVE-2026-92842) — MEDIUM 5.9 · 2026-09-25
- [CVE-2026-93682](https://intel.threadlinqs.com/cve/CVE-2026-93682) — MEDIUM 5.8 · 2026-09-25
- [CVE-2026-6103](https://intel.threadlinqs.com/cve/CVE-2026-6103) — MEDIUM 4.3 · 2026-09-25
- [CVE-2026-91769](https://intel.threadlinqs.com/cve/CVE-2026-91769) — MEDIUM 4.3 · 2026-09-25
- [CVE-2025-1218](https://intel.threadlinqs.com/cve/CVE-2025-1218) — LOW 3.4 · 2026-09-25

## Products affected

Threadlinqs normalises CPE and CNA product records across all 14 CVEs; 1 distinct PHP Group product is affected. The most frequently affected:

- PHP — 14 CVEs

## Threat activity

6 tracked threat campaigns reference PHP Group products or exploit PHP Group CVEs:

- [Multiple PHP Vulnerabilities Enable Denial of Service, TLS Verification Bypass, and Credential Leakage (CVE-2026-91765, CVE-2026-91768, CVE-2026-6103 and 8 Others) — GovCERT.HK A26-09-40](https://intel.threadlinqs.com/threat/TL-2026-2658) — MEDIUM — 2026-09-25
- [Dissection of a PHP Backdoor Leveraging php-win.exe for Stealthy Windows Persistence](https://intel.threadlinqs.com/threat/TL-2026-2149) — MEDIUM — 2026-08-26
- [Multiple Vulnerabilities in PHP (GovCERT.HK A26-07-52): Phar Symlink DoS, Bundled-libgd GIF Memory Corruption, pgsql SQL Injection, and BCMath Out-of-Bounds Write (CVE-2026-7260, CVE-2026-9672, CVE-2026-17543, CVE-2026-17544)](https://intel.threadlinqs.com/threat/TL-2026-1782) — HIGH — 2026-07-31
- [HollowByte: OpenSSL Pre-Authentication TLS DoS Flaw Bloats Server Memory With 11-Byte Payload](https://intel.threadlinqs.com/threat/TL-2026-1457) — MEDIUM — 2026-07-17
- [OpenSSL "HollowByte" TLS Handshake Memory-Amplification DoS (No CVE Assigned)](https://intel.threadlinqs.com/threat/TL-2026-1459) — MEDIUM — 2026-07-17
- [APT35 (Charming Kitten) GCC Pre-Positioning Cyber Reconnaissance Campaign Enabling Kinetic Targeting](https://intel.threadlinqs.com/threat/TL-2026-0339) — CRITICAL — 2026-04-09

## Threat actors targeting PHP Group

Named threat actors attributed to campaigns that involve PHP Group products or CVEs, with the number of linked campaigns:

- [APT35](https://intel.threadlinqs.com/actor/APT35) — 1 campaign
- [APT42](https://intel.threadlinqs.com/actor/APT42) — 1 campaign

## How to prioritise PHP Group patching

This order follows the data Threadlinqs holds for PHP Group, not a generic severity checklist:

- No PHP Group CVE is in CISA KEV yet, so rank by exploit probability instead.
- Outside KEV, the highest EPSS scores are [CVE-2026-17544](https://intel.threadlinqs.com/cve/CVE-2026-17544) (0.4%), [CVE-2026-17543](https://intel.threadlinqs.com/cve/CVE-2026-17543) (0.4%), [CVE-2026-7260](https://intel.threadlinqs.com/cve/CVE-2026-7260) (0.2%).
- 0 CVEs score Critical and 3 High on CVSS v3 (maximum 8.1, average 6.1); sequence these after KEV and high-EPSS items.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/php-group
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
