# PHP security release fixes an IPv6 FastCGI ACL bypass across every supported branch

PHP 8.5.11, 8.4.26, 8.3.35 and 8.2.34 are coordinated security releases fixing a PHP-FPM IPv6 access-control bypass, TLS hostname-verification flaws and other vulnerabilities across every supported PHP branch.

The sharpest operational trap is CVE-2026-91768: PHP-FPM’s listen.allowed_clients can treat an allowed IPv6 address as an entire /96 prefix. Teams relying on that ACL should patch rather than assuming the configured address restriction is exact.

- Status: Active
- Published: 2026-09-27T11:25:50+13:00
- Updated: 2026-09-27T11:25:50+13:00
- Categories: Web Development, PHP
- Tags: CVE-2026-91768, CVE-2026-91769, PHP-FPM, security
- Canonical HTML: https://beyondthe.news/dossiers/php-september-2026-security-release-fastcgi-ipv6-acl-tls-cves

## What changed

On September 24 PHP shipped security releases 8.5.11, 8.4.26, 8.3.35 and 8.2.34. The coordinated fixes include CVE-2026-91768 in PHP-FPM: the IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed_clients effectively matches a /96 prefix rather than one exact address. The releases also fix CVE-2026-91769, where TLS hostname verification can fall back to a certificate Common Name after a Subject Alternative Name mismatch, and additional flaws across OpenSSL, SOAP, Phar, HTTP streams, mysqlnd and other components.

## Why it matters

PHP remains underneath a large amount of ordinary web infrastructure, and this release is relevant even when application code has not changed. The FPM flaw weakens a network access-control boundary operators may believe is exact; an attacker still needs network reachability and an IPv6 source sharing the permitted /96, so this is not universal internet-facing RCE. The TLS bug matters on outbound connections because a failed SAN match should not be rescued by a weaker CN check. Because fixes landed across all supported branches at once, operators can patch in place rather than making a major-version migration.

## The FPM ACL can be broader than its configuration looks

CVE-2026-91768 affects IPv6 handling in PHP-FPM listen.allowed_clients. Only 12 bytes of the 16-byte IPv6 address were compared, turning an intended exact-address allow rule into a /96-prefix match. Exploitation requires the attacker to reach the FastCGI listener from an IPv6 address sharing that prefix.

## TLS hostname checking also received security fixes

CVE-2026-91769 fixes hostname verification falling back to the certificate Common Name after a Subject Alternative Name mismatch. The same release family also fixes CVE-2026-91767, a heap overread in wildcard-name matching for crafted server certificates.

## This is a coordinated supported-branch patch

PHP published fixed releases for 8.2, 8.3, 8.4 and 8.5 on September 24 and labels them security releases. That gives production users a same-branch remediation path.

## Key details

- Fixed releases are PHP 8.5.11, 8.4.26, 8.3.35 and 8.2.34.
- CVE-2026-91768 is an IPv6 ACL bypass in PHP-FPM listen.allowed_clients caused by comparing 12 of 16 address bytes.
- The resulting match boundary is an IPv6 /96 prefix rather than one exact address.
- CVE-2026-91769 fixes TLS hostname verification falling back to CN after SAN mismatch.
- The release family contains additional security fixes across OpenSSL, SOAP, Phar, HTTP streams and mysqlnd.

## Builder takeaways

- Patch supported PHP branches to 8.5.11, 8.4.26, 8.3.35 or 8.2.34 as applicable.
- If PHP-FPM FastCGI is reachable beyond localhost, inspect listen.allowed_clients and do not treat its pre-patch IPv6 check as an exact-address security boundary.
- Use firewall or network-layer controls around FastCGI rather than relying on the PHP-FPM ACL as the only isolation layer.
- Treat outbound TLS verification fixes as relevant to PHP services that call HTTPS endpoints, not only to public-facing web requests.

## What to watch

- Whether distributions backport the fixes under older package version strings.
- Any evidence of exploitation of CVE-2026-91768 or the TLS verification flaws.
- Operational reports showing common PHP-FPM deployment patterns exposed to the IPv6 ACL condition.

## Uncertainties

- CVE-2026-91768 requires network reachability plus an IPv6 source within the same /96 as an allowed address; exposure varies materially by deployment.
- No evidence reviewed in this pass establishes active exploitation of these PHP vulnerabilities.
- Distribution packages may carry backported fixes without matching upstream version numbers exactly.

## Sources

- [PHP 8 ChangeLog](https://www.php.net/ChangeLog-8.php) — PHP · primary changelog · 2026-09-24T00:00:00+12:00. Primary details for CVE-2026-91768, CVE-2026-91769 and the other fixes in the supported-branch security releases.
- [PHP security releases — September 24, 2026](https://www.php.net/) — PHP · primary release announcement · 2026-09-24T00:00:00+12:00. Confirms 8.5.11, 8.4.26, 8.3.35 and 8.2.34 are security releases and recommends upgrading.
- [PHP 8.5.11 Patches 11 CVEs, Including a SOAP Server Crash](https://phpnews.net/php-8-5-11) — PHP News · specialist ecosystem coverage · 2026-09-24T00:00:00+12:00. Specialist PHP framing of the coordinated security release and affected components.

