The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
## 3.0.4 CVE-2019-3465 / https://simplesamlphp.org/security/201911-01
## 2.1.1 CVE-2019-3465 / https://simplesamlphp.org/security/201911-01 ## 2.1.0 Backports changes from 3.0 branch
## 3.0.4 CVE-2019-3465 / https://simplesamlphp.org/security/201911-01
## 3.0.4 CVE-2019-3465 / https://simplesamlphp.org/security/201911-01
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in in denial of service, informati…
Fedora released an update for php-pear-PHP-CodeSniffer (4.0.4) with security fixes and enhancements, emphasizing the need for users to promptly update due to v…
An update for PHP 8.4 on Rocky Linux 10 addresses a denial of service vulnerability and includes various bug fixes and enhancements, with a CVSS base score of …
Debian has released a security advisory for PHP 8.2, addressing vulnerabilities that could lead to denial of service and SQL injection. Users are urged to upgr…
Mageia 10 has released updates for php 8.4 to address multiple security vulnerabilities, as identified by CVEs CVE-2026-17544, CVE-2026-9672, CVE-2026-17543, a…
Oracle Linux 10 has updated RPM packages for PHP 8.4.23, addressing CVE-2026-14355, and is available for both x86_64 and aarch64 architectures through the Unbr…
It was discovered that a buffer overflow in the implementation of AES Key Wrap with Padding in the openssl extension of PHP, a widely-used open source general …
It was discovered that a buffer overflow in the implementation of AES Key Wrap with Padding in the openssl extension of PHP, a widely-used open source general …
CVE-2026-48907 in the Joomla JCE plugin lets unauthenticated attackers drop PHP web shells with a single crafted request. Here is how the attack works and how …
Drupal has issued an alert stating that it intends to release a "core security release" for all supported branches on May 20, 2026, from 5-9 p.m. UTC."The Drup…
Two vulnerabilities were discovered in phpseclib, a PHP Secure Communications Library. CVE-2023-52892 Some characters in Subject Alternative Name fields in TLS…
It was discovered that the AES-CBC implementation in the PHP Secure Communications Library was susceptible to a padding oracle timing attack. For the oldstable…
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in server side request forgery or …
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, ci…
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language which could result in denial of service or server side…
This is a security update to the stable version 1.6 of Roundcube Webmail. It provides fixes to recently reported security vulnerabilities: Fix Post-Auth RCE vi…
Alright, Linux admins and security pros, let's talk WordPress . I know''typically, "WordPress" doesn't top the list of thrilling topics in our corner of the te…
Kirill Firsov discovered that Roundcube, a skinnable AJAX based webmail solution for IMAP servers, was performing PHP Object deserialization on unvalidated inp…
Security vulnerabilities were found in symfony, a PHP framework for web and console applications and a set of reusable PHP components, which could lead to vali…
Keeping WordPress secure can be challenging, especially when considering Linux security concerns in a typical LAMP stack setup. Most WordPress security issues …