On April 27, 2018, the Multi-State Information Sharing and Analysis Center (MS-ISAC) warned that multiple PHP vulnerabilities could allow arbitrary code execution or denial of service. A Hong Kong government advisory published three days later listed branch-specific PHP versions below which installations were affected. Those thresholds describe the 2018 advisory only; they do not establish whether a PHP installation is vulnerable today.
What PHP vulnerabilities did MS-ISAC warn about?
CyberScoop reported on April 27, 2018, that MS-ISAC had issued an advisory about multiple PHP vulnerabilities. MS-ISAC serves state, local, tribal and territorial government agencies, and characterized the risk as high for government organizations and businesses of all sizes.
The advisories described potential arbitrary code execution and denial of service. Depending on the privileges assigned to the affected application, a successful attacker might gain substantial control over the system. CyberScoop quoted the advisory warning: “Depending on the privileges associated with the application, an attacker could install programs; view, change, or delete data; or create new accounts with full user rights.”
Which PHP versions did the 2018 advisory list as affected?
GovCERT.HK’s April 30, 2018 advisory listed versions before the following branch-specific thresholds as affected:
#1 Best Overall
| PHP branch | Threshold in the April 2018 advisory | Versions listed as affected |
|---|---|---|
| 5.6 | 5.6.36 | Before 5.6.36 |
| 7.0 | 7.0.30 | Before 7.0.30 |
| 7.1 | 7.1.17 | Before 7.1.17 |
| 7.2 | 7.2.5 | Before 7.2.5 |
These are historical fix thresholds, not current PHP security guidance. The cited advisories do not establish the status of present-day PHP releases or any particular installation.
What could an attacker do?
The reported outcomes included executing code on an affected system or causing denial of service. The degree of possible damage could depend on the privileges under which the vulnerable application ran: the warning described possible program installation, access to alter or delete data, or creation of accounts with full user rights. These were potential impacts, not a report of a specific number of attacks or confirmed incidents.
Rank #2
What did administrators need to do?
The historical advisories recommended updating affected software. CyberScoop also reported MS-ISAC’s advice to check for unauthorized system changes before applying patches. For administrators responding to an advisory, that sequence matters: inspect the system for signs of compromise as well as bringing affected software up to the applicable fixed version.
For a decision today, first inventory the PHP versions actually deployed and the applications or dependencies that bundle or rely on PHP. Then consult current vendor security guidance for those components and the relevant supported branch. The 2018 thresholds above cannot determine whether a current deployment is at risk.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesRank #3
How does the Drupal reference relate?
CyberScoop separately noted that Drupal had announced a patch the prior month for a remote-code-execution flaw. That was a distinct event, not one of the PHP vulnerabilities in the April 2018 MS-ISAC warning.
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

