Vulnerability

CVE-2026-17543

CRITICAL 9.8

CVE-2026-17543 is a critical-severity vulnerability (CVSS v3.1 9.8). As of 2026-10-08, 36 458 hosts in our data show software it affects on an open service in at least 15 countries.

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

Published
2026-07-30
Last modified
2026-08-05
CVSS score
9.8 CVSS v3.1
CVSS vector (v3.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploit likelihood (EPSS)
0.3% in the next 30 days (higher than 24% of CVEs)

Exposure in our data

36 458 hosts

Hosts whose banner shows an affected software version on a service open at their latest check.

Not counted: 9 hosts with this CVE only from an older observation.

Not counted: 6 hosts where the software version is too vague to tell (only a major release).

Not counted: 956 more on distribution builds that may be patched (the distribution may have backported the fix without changing the version).

14 more hosts had it earlier (the software version has since changed or the service is gone).

Counted 2026-10-08 03:20 UTC

By country

Netherlands NL6 836
United States US6 743
Germany DE5 504
United Kingdom GB1 369
Romania RO1 321
India IN1 311
France FR1 278
Japan JP1 260
China CN1 076
Hong Kong HK746
Bulgaria BG712
Russia RU679
Italy IT554
Singapore SG527
Spain ES417

Affected software seen

php 8.2.87 734
php 8.3.312 954
php 8.2.122 772
php 8.2.301 770
php 8.2.311 651
php 8.3.301 648
php 8.3.321 387
php 8.2.291 384
php 8.2.281 032
php 8.4.21965
php 8.3.28691
php 8.5.5570