Arab Press

بالشعب و للشعب
Wednesday, Nov 12, 2025

Hackers are using a bug in PHP7 to remotely hijack web servers

Hackers are using a bug in PHP7 to remotely hijack web servers

The PHP programming language underpins much of the Internet. It forms the basis of popular content management systems like WordPress and Drupal, as well as more sophisticated web applications, like Facebook (kinda). Therefore, it’s a huge deal whenever researchers identify a security vulnerability within it.
A couple of days ago, Emil ‘Neex’ Lerner, a Russia-based security researcher, disclosed a remote-code execution vulnerability in PHP 7 – the latest iteration of the hugely popular web development language.

With this vulnerability, which has the CVE-ID of 2019-11043, an attacker could force a remote web server to execute their own arbitrary code simply by accessing a crafted URL. The attacker only needs to add “?a=” to the website address, followed by their payload.

As pointed out by Catalin Cimpanu in ZDNet, this attack drastically lowers the barrier to entry for hacking a website, simplifying it to the point where even a non-technical user could abuse it.

Fortunately, the vulnerability only impacts servers using the NGINX web server with the PHP-FPM extension. PHP-FPM is a souped-up version of FastCGI, with a few extra features designed for high-traffic websites.

While neither of those components are necessary to use PHP 7, they remain stubbornly common, particularly in commercial environments. Cimpanu points out that NextCloud, a large productivity software provider, uses PHP7 with NGINX and PHP-FPM. It’s since released a security advisory to clients urging them to update warning them of the issue and imploring them to update their PHP install to the latest version.

Site owners who are unable to update their PHP install can mitigate the problem by setting a rule within the standard PHP mod_security firewall. Instructions on how to do this can be found on the website of appsec startup Wallarm.

This vulnerability has all the hallmarks of a security perfect storm. Not only are multiple environments at risk, but it’s also trivially simple for an attacker to exploit the vulnerability. And while patches and workarounds currently exist, as we’ve witnessed previously, not everyone is particularly proactive with their security. Two-and-a-half years after the well-publicized Heartbleed OpenSSL bug was disclosed, over 200,000 servers remained vulnerable.

And there’s evidence to suggest that hackers are already exploiting this critical PHP issue. Threat intel firm BadPackets has already confirmed to ZDNet that bad actors are already using this vulnerability to commandeer servers.

Things are going to get worse before they get better.
Newsletter

Related Articles

Arab Press
0:00
0:00
Close
Cristiano Ronaldo Embraces Saudi Arabia’s 2034 World Cup Vision with Key Role
Saudi Arabia’s Execution Campaign Escalates as Crown Prince Readies U.S. Visit
Trump Unveils Middle East Reset: Syria Re-engaged, Saudi Ties Amplified
Saudi Arabia to Build Future Cities Designed with Tourists in Mind, Says Tourism Minister
Saudi Arabia Advances Regulated Stablecoin Plans with Global Crypto Exchange Support
Saudi Arabia Maintains Palestinian State Condition Ahead of Possible Israel Ties
Chinese Steel Exports Surge 41% to Saudi Arabia as Mills Pivot Amid Global Trade Curbs
Saudi Arabia’s Biban Forum 2025 Secures Over US$10 Billion in Deals Amid Global SME Drive
Saudi Arabia Sets Pre-Conditions for Israel Normalisation Ahead of Trump Visit
MrBeast’s ‘Beast Land’ Arrives in Riyadh as Part of Riyadh Season 2025
Cristiano Ronaldo Asserts Saudi Pro League Outperforms Ligue 1 Amid Scoring Feats
AI Researchers Claim Human-Level General Intelligence Is Already Here
Saudi Arabia Pauses Major Stretch of ‘The Line’ Megacity Amid Budget Re-Prioritisation
Saudi Arabia Launches Instant e-Visa Platform for Over 60 Countries
Dick Cheney, Former U.S. Vice President, Dies at 84
Saudi Crown Prince to Visit Trump at White House on November Eighteenth
Trump Predicts Saudi Arabia Will Normalise with Israel Ahead of 18 November Riyadh Visit
Entrepreneurial Momentum in Saudi Arabia Shines at Riyadh Forward 2025 Summit
Saudi Arabia to Host First-Ever International WrestleMania in 2027
Saudi Arabia to Host New ATP Masters Tournament from 2028
Trump Doubts Saudi Demand for Palestinian State Before Israel Normalisation
Viral ‘Sky Stadium’ for Saudi Arabia’s 2034 World Cup Debunked as AI-Generated
Deal Between Saudi Arabia and Israel ‘Virtually Impossible’ This Year, Kingdom Insider Says
Saudi Crown Prince to Visit Washington While Israel Recognition Remains Off-Table
Saudi Arabia Leverages Ultra-Low Power Costs to Drive AI Infrastructure Ambitions
Saudi Arabia Poised to Channel Billions into Syria’s Reconstruction as U.S. Sanctions Linger
Smotrich’s ‘Camels’ Remark Tests Saudi–Israel Normalisation Efforts
Saudi Arabia and Qatar Gain Structural Edge in Asian World Cup Qualification
Israeli Energy Minister Delays $35 Billion Gas Export Agreement with Egypt
Fincantieri and Saudi Arabia Agree to Build Advanced Maritime Ecosystem in Kingdom
Saudi Arabia’s HUMAIN Accelerates AI Ambitions Through Major Partnerships and Infrastructure Push
IOC and Saudi Arabia End Ambitious 12-Year Esports Games Partnership
CSL Seqirus Signs Saudi Arabia Pact to Provide Cell-Based Flu Vaccines and Build Local Production
Qualcomm and Saudi Arabia’s HUMAIN Team Up to Deploy 200 MW AI Infrastructure
Saudi Arabia’s Economy Expands Five Percent in Third Quarter Amid Oil Output Surge
China’s Vice President Han Zheng Meets Saudi Crown Prince as Trade Concerns Loom
US and Qatar Warn EU of Trade and Energy Risks from Tough Climate Regulation
AI and Cybersecurity at Forefront as GITEX Global 2025 Kicks Off in Dubai
EU Deploys New Biometric Entry/Exit System: What Non-EU Travelers Must Know
Ex-Microsoft Engineer Confirms Famous Windows XP Key Was Leaked Corporate License, Not a Hack
Israel and Hamas Agree to First Phase of Trump-Brokered Gaza Truce, Hostages to Be Freed
Syria Holds First Elections Since Fall of Assad
Altman Says GPT-5 Already Outpaces Him, Warns AI Could Automate 40% of Work
Trump Organization Teams with Saudi Developer on $1 Billion Trump Plaza in Jeddah
Archaeologists Recover Statues and Temples from 2,000-Year-Old Sunken City off Alexandria
Colombian President Petro Vows to Mobilize Volunteers for Gaza and Joins List of Fighters
Nvidia and Abu Dhabi’s TII Launch First AI-&-Robotics Lab in the Middle East
UK, Canada, and Australia Officially Recognise Palestine in Historic Shift
Dubai Property Boom Shows Strain as Flippers Get Buyer’s Remorse
JWST Data Brings TRAPPIST-1e Closer to Earth-Like Habitability
×