What changed
On September 24 PHP shipped security releases 8.5.11, 8.4.26, 8.3.35 and 8.2.34. The coordinated fixes include CVE-2026-91768 in PHP-FPM: the IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed_clients effectively matches a /96 prefix rather than one exact address. The releases also fix CVE-2026-91769, where TLS hostname verification can fall back to a certificate Common Name after a Subject Alternative Name mismatch, and additional flaws across OpenSSL, SOAP, Phar, HTTP streams, mysqlnd and other components.
Why it matters
PHP remains underneath a large amount of ordinary web infrastructure, and this release is relevant even when application code has not changed. The FPM flaw weakens a network access-control boundary operators may believe is exact; an attacker still needs network reachability and an IPv6 source sharing the permitted /96, so this is not universal internet-facing RCE. The TLS bug matters on outbound connections because a failed SAN match should not be rescued by a weaker CN check. Because fixes landed across all supported branches at once, operators can patch in place rather than making a major-version migration.
The FPM ACL can be broader than its configuration looks
CVE-2026-91768 affects IPv6 handling in PHP-FPM listen.allowed_clients. Only 12 bytes of the 16-byte IPv6 address were compared, turning an intended exact-address allow rule into a /96-prefix match. Exploitation requires the attacker to reach the FastCGI listener from an IPv6 address sharing that prefix.
TLS hostname checking also received security fixes
CVE-2026-91769 fixes hostname verification falling back to the certificate Common Name after a Subject Alternative Name mismatch. The same release family also fixes CVE-2026-91767, a heap overread in wildcard-name matching for crafted server certificates.
This is a coordinated supported-branch patch
PHP published fixed releases for 8.2, 8.3, 8.4 and 8.5 on September 24 and labels them security releases. That gives production users a same-branch remediation path.