Kai Ole Hartwig

Review 2026: Security advisories from May to September

From May to September 2026, I wrote up a lot of security advisories one by one. That was too many. This page collects the ones that mattered for PHP, TYPO3 and Kubernetes operators but don't need a post of their own. One short paragraph each. The detailed posts on my own stack are under Advisories.

PHP, Symfony and Composer

Symfony Process CVE-2026-24739 (May). Under MSYS2 and Git Bash on Windows, the Process component escaped arguments containing an equals sign incorrectly. It affects Windows developer machines, not your Linux servers.

Symfony follow-up from 20 May. The webhook parsers for Mailtrap, Mailjet, LOX24 and Twilio never checked the secret (CVE-2026-45754, -45755, -47212). There's also a ReDoS in the JsonPath parser (CVE-2026-45756).

PHP 8.4.21 and 8.3.31 (7 May). A coordinated security release for 8.2.31, 8.3.31, 8.4.21 and 8.5.6, including a fix in PDO Firebird (CVE-2025-14179).

PHP JPEG handling (CVE-2025-14177). On 15 May, PT SWARM published a write-up on two memory-safety bugs in getimagesize() and iptcembed(). Both have been patched since November 2025.

PHP 8.6 RC2 (23 September). The stable release is announced for November 2026. New features include Partial Function Application and clamp(). Plan for the deprecations early.

Composer 2.10 and the Packagist roadmap (27 May). Announced: dependency policies, stable version immutability and mandatory MFA for maintainers.

TYPO3 maintenance releases

TYPO3 14.3.1 and 13.4.29 (12 May). Maintenance releases without a security advisory, with a raised memory limit and a drag-and-drop fix.

TYPO3 14.3.2 and 13.4.30 (26 May). Pure maintenance releases with raised Symfony and Composer constraints.

npm supply chain

EVM/DeFi wave (6 May). Six malicious Web3 packages, including viem-core, hardhat-core-utils and foundry-utils, four days after node-env-resolve.

node-ipc (14 May). Three tampered versions with a credential stealer sat in the npm registry for eleven hours. The attackers got in through the maintainer's domain.

Shai-Hulud against @antv (19 May). 323 npm packages in the @antv cluster within one hour. The densest wave of the series so far.

vpmdhaj typosquats (28 May). Microsoft Threat Intelligence disclosed 14 packages posing as OpenSearch and Elasticsearch tools. They went after AWS and Vault tokens.

jscrambler 8.14.0 to 8.20.0 (11 July). A compromised publish credential put a Rust infostealer into the package. It targeted cloud keys, wallets, AI tool configs and Kubernetes access. The fix is 8.22.0.

AsyncAPI (14 July). An unmerged pull_request_target flaw let attackers steal the publish token. The affected packages had around 2.9 million weekly downloads.

tw-pkgprobe-7731 (24 September). The package posed as a Twilio bug bounty tool and exfiltrated the account SID and auth token from environment variables.

Web servers, TLS and Redis

nginx-poolslip (21 May). Vega-AI reported an unauthenticated RCE path in the memory pool of nginx 1.31.0. At the time of the report there was neither a CVE nor a patch.

HTTP/2 Bomb (2 June). A remote DoS against the default HTTP/2 configuration of nginx, Apache httpd, IIS, Envoy and Pingora.

OpenSSL security release (9 June). Ten CVEs, one of them High: CVE-2026-45447, a use-after-free in PKCS7_verify(). Fixed in 4.0.1, 3.6.3, 3.5.7, 3.4.6 and 3.0.21.

HollowByte. An 11-byte TLS packet with a wrong length field makes OpenSSL servers reserve memory. No CVE, but patched in the same versions.

Redis Streams and RedisBloom (23 July). New memory bugs close to CVE-2026-25589 and CVE-2026-25243. Redis shipped seven patch releases.

Linux kernel

PamDOORa (May). A PAM-based Linux backdoor with a magic password, credential harvesting and log tampering.

Fragnesia, CVE-2026-46300. The third XFRM LPE in three weeks. A logic bug in ESP-in-TCP creates a write primitive into the page cache.

DirtyDecrypt, CVE-2026-31635. Local privilege escalation in rxgk_decrypt_skb. V12 published a working PoC.

ptrace, CVE-2026-46333 (20 May). A logic bug in __ptrace_may_access() present since v4.10-rc1. Qualys published the full advisory.

Kernel wave, 28 to 30 May. 117 CVEs rated CVSS 7 or higher in 48 hours. The headline finding was CVE-2026-46227 in SCTP_SENDALL.

Bad Epoll, CVE-2026-46242. Use-after-free in fs/eventpoll.c, local root on Linux 6.4+ and Android. Fixed in Linux 7.1.

RefluXFS, CVE-2026-64600 (23 July). A race in the XFS reflink path that is about nine years old. A PoC is public.

Why these belong together: for container hosts, they all mean the same thing. Local privilege escalation on the node is a container escape. Patch your nodes promptly.

AI agents and developer tools

LiteLLM, Flowise and MS-Agent (May). Three CVEs show the same weakness: agent frameworks run with too many privileges.

vm2 (7 May). Twelve critical sandbox escapes in the Node library, CVSS 9.8 and 10.0.

Semantic Kernel (7 May). Microsoft disclosed CVE-2026-25592 and CVE-2026-26030. There, prompts turn into a shell.

VS Code and Copilot (May Patch Tuesday). Six vulnerabilities, including RCE and a workspace trust bypass.

TeamPCP claim (May). The claim was a breach of around 4,000 internal GitHub repos. It came from the attackers themselves, who offered the data for 50,000 USD on BreachForum.

Fake install pages for Claude Code and Gemini CLI (26 and 28 May). EclecticIQ and Cyderes documented SEO poisoning campaigns that deliver a fileless infostealer. Only install developer tools from the vendor's own site.

Nx Console, CVE-2026-48027 (27 May). A compromised version of the VS Code extension, added to the KEV list by CISA.

NVIDIA Verified Agent Skills (19 May). Signed SKILL.md packages with scanning and OpenSSF Model Signing.

VS Code webview escape. One click in github.dev was enough to steal a token with write access to the repos.

OpenAI Lockdown Mode (7 June). Browsing, Deep Research and Agent Mode can be switched off deterministically.

Friendly Fire (9 July). README injection gets Claude Code and OpenAI Codex in auto mode to run hidden payloads.

GhostApproval (8 July). Symlinks let six AI coding agents write outside the workspace (CVE-2026-12958, CVE-2026-50549).

Azure DevOps MCP server (22 July). Invisible HTML comments in PR descriptions hijack AI review agents. No CVE, no patch.

Ruflo MCP Bridge, CVE-2026-59726. Unauthenticated RCE with CVSS 10.0 via port 3001.

Consul MCP Server, HCSEC-2026-24. SSRF and cross-tenant credential reuse in 0.1.0 to 0.1.3. Fixed in 0.1.4.

Git hosting and identity

Gitea, CVE-2026-20896. Docker images trusted the X-WEBAUTH-USER header from any IP. CVSS 9.8, actively scanned since 7 July. Fixed in 1.26.4.

Gitea, CVE-2026-60004. The diffpatch endpoint allowed planting a Git hook and thus RCE. CVSS 9.8, actively exploited, fixed in 1.27.1.

Keycloak, CVE-2026-9795 (28 May). Privilege escalation in Fine-Grained Admin Permissions v2, CVSS 7.3.

Contact

Sounds like a fit?
Then write to me.

No form marathon, no sales funnel. A short message — I get back to you personally and tell you honestly whether I can help.

Book a call