CVE-2026-91769: PHP PHP vulnerability
Published Sep 24, 2026
·Updated
Fixed (TLS hostname verification falls back to CN after SAN mismatch). (CVE-2026-91769)
Affected Software
1 affected componentFixes available
PHP PHP<8.4.26
8.4.26
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.4.26
Event History
Sep 24, 2026
CVE Published
via PHP·12:00 AM
Data Sourced
via PHP·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
Which PHP release documentation should be checked to verify this fix?
The provided reference points to the PHP 8.3.35 changelog. The available data does not identify affected version ranges or fixes in other release branches.