Vulnerability threat dossier

CVE-2019-11043

phpphp

In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.

VTP deterministic threat59.5of 100 · CVSS excluded

VTP analyst assessment

PHP-FPM RCE with known global exploitation

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateCANDIDATE CREATED
AI priorityHIGH
AI confidence94%
Public exploitation · VTP factKEV

Assessment

Certain PHP-FPM configurations in PHP 7.1 before 7.1.33, 7.2 before 7.2.24, and 7.3 before 7.3.11 permit a buffer overwrite that can enable remote code execution. The CVSS 3.1 score is 8.7, CISA KEV establishes known global exploitation and known ransomware-campaign use, and a public exploit-oriented template is reported.

Why it matters

  • Network-reachable exploitation requires no privileges or user interaction under the supplied CVSS vector, although attack complexity is high.
  • Successful exploitation can compromise confidentiality and integrity through remote code execution.
  • KEV and ransomware-use status establish material global threat context, not VTP observation.

Evidence

1 record references and 3 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

Exposure depends on the specific FPM configuration and affected PHP version.

The supplied template's functional reliability and current use are not established.

No first-party activity evidence is supplied.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

Presence of affected PHP-FPM versions and vulnerable configurations.

AI baseline history (1)
  1. BASELINE ASSESSED
    PHP-FPM RCE with known global exploitationgpt-5.6-sol · high
Technical severityHIGHCVSS 8.7 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityPOCReliability not implied
EPSS1.00100th percentile · prediction
Evidence confidence90%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    A proof of concept is reported; functional reliability is not established.

  3. 03

    EPSS is 1.00; this is predictive context, not exploitation evidence.

  4. 04

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

EXPLOIT TEMPLATE AVAILABLEPublic exploit-oriented template available
KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

2publications detected
2underlying evidence chains

0 primary sources · 0 dependent secondary reports · 1 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOIT TEMPLATE AVAILABLEPUBLIC EXPLOIT TEMPLATE
90%claim confidence
PRIMARYcorpus:NUCLEI:2d5f9b585251080d44be6d0dcb305da71f0a4863ACTIVE
Evidence
04

Event history

Threat timeline

  1. 14:5916 Sept
    EXPLOIT SOURCE UPDATE

    New exploit-source update

    ProjectDiscovery Nuclei Templates Releases published evidence linked to CVE-2019-11043.

  2. 03:3126 Aug
    EXPLOIT TEMPLATE AVAILABLE

    Public exploit-oriented template available

    ProjectDiscovery nuclei-templates published new or materially changed exploit-oriented tooling for this CVE. This is availability evidence, not evidence of exploitation in the wild.

  3. 00:0025 Mar
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

05

Original publications

Source record

Nuclei Templates v10.4.9 - Release Notes

New Templates Added: 123 | CVEs Added: 85 | First-time contributions: 15 🔥 Release Highlights 🔥 [ CVE-2026-86207 ] N-able N-central - Authentication Bypass ( @rapid7 , @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-85706 ] GitLab CE/EE <=19.1.7/19.2.5/19.3.1 - Arbitrary File Read ( @flx ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-83548 ] SonicWall SMA1000 WorkPlace - Unauthenticated SSRF to CouchDB ( @rapid7 , @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-82329 ] JFrog Artifactory Access Blank Join Key Authentication Bypass ( @johnk3r , @pruva ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-82222 ] GiveWP <= 4.16.7.1 - Remote Code Execution (@0x_Akoko, @pdteam ) [critical] (vKEV) 🔥 [ CVE-2026-81578 ] PaperCut NG/MF <=26.0.4 - Unauthenticated ConfigEditor Access via Tapestry Complex-Direct ( @darses , @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-73570 ] Zimbra Collaboration Suite < 10.1.20 - OS Command Injection (@0x_Akoko, @ritikchaddha ) [high] (kev) (vKEV) 🔥 [ CVE-2026-55040 ] Microsoft SharePoint Server - JWT Authentication Bypass ( @sfewer-r7 , @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-48558 ] SimpleHelp <=5.5.15 - OIDC JWT Authentication Bypass (@0x_Akoko, @pdteam ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-41948 ] Dify <=1.14.1 - Unauthenticated Plugin Daemon Path Traversal ( @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-32475 ] Elementor Pro <=4.2.1 - Unauthenticated Arbitrary File Upload via Form Handler ( @pdteam ) [critical] (vKEV) 🔥 [ CVE-2026-18963 ] Keycloak < 26.7.2 - Unauthenticated Account Takeover via Reset-Credentials Bypass ( @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-18577 ] N-able N-central < 2026.3.1.10 - Authentication Bypass ( @patrick-threatmate ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-9586 ] Sangoma Switchvox < 8.4.0.2 - Unauthenticated SQL Injection ( @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-1281 ] Ivanti EPMM <=12.7.0.0 - Unauthenticated Code Injection ( @rxerium ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-0768 ] Langflow <=1.2.x - Unauthenticated Remote Code Execution via validate_code ( @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2024-1708 ] ConnectWise ScreenConnect <= 23.9.7 - Path Traversal ( @Popy21 ) [high] (kev) (vKEV) 🔥 [ CVE-2023-54391 ] Proxmox VE - Default Credentials with TFA Bypass ( @dhiyaneshdk , @0x_Akoko) [critical] (vKEV) 🔥 [ CVE-2020-10221 ] rConfig <= 3.9.4 - Authenticated OS Command Injection ( @Jayachandran from Securin Labs ( https://securin.io )) [high] (kev) (vKEV) 🔥 [ CVE-2019-11043 ] PHP-FPM Path Info Buffer Underflow - Remote Code Execution ( @prasath from Securin Labs ( https://securin.io )) [critical] (kev) (vKEV) 🔥 [ CVE-2017-7504 ] JBossMQ HTTP Invocation Layer (HTTPServerILServlet) - Unauthenticated Java Deserialization ( @Jayachandran ) [critical] (vKEV) 🔥 What's Changed Bug Fixes Fixed the CVE-2026-41042 template filename so the template loads correctly (PR #17024 , Issue #17022 ). Corrected the filename casing on CVE-2025-14047 .yaml (PR #16994 ). Resolved an unresolved nested payload variable in CVE-2026-4257 that stopped the WordPress Contact Form by Supsystic template running on nuclei v3.11.1 (PR #17039 ). Fixed the matched_feature extractor in CVE-2026-76904 .yaml (PR #16969 ). Corrected the author field in CVE-2026-61511 .yaml (PR #16976 ). Removed six imprecise CVE templates whose proofs of concept were not reliable — CVE-2016-3714 , CVE-2018-10933 , CVE-2018-15708 , CVE-2019-8942 , CVE-2019-17554 and CVE-2020-2555 (PR #16567 ). False Negatives CVE-2021-43798 — the Grafana arbitrary file read template now fires on instances sitting behind an nginx reverse proxy (PR #17185 ). CVE-2018-3760 — restored broken detection on Ruby on Rails local file inclusion using disable-path-automerge and a flow block (PR #17235 ). CVE-2021-34429 — replaced unsafe with disable-path-automerge so the Jetty request path is no longer duplicated (PR #17236 ). CVE-2024-52433 — the My Geo Posts Free template could never match a genuin

CVE-2016-3714CVE-2017-7504CVE-2017-8225CVE-2018-10933CVE-2018-15708CVE-2018-3760CVE-2019-11043CVE-2019-17554CVE-2019-8942CVE-2020-10221CVE-2020-2555CVE-2020-29134CVE-2021-34429CVE-2021-43798CVE-2022-39258CVE-2023-54391CVE-2024-1708CVE-2024-52433CVE-2025-14047CVE-2025-14998CVE-2025-15403CVE-2025-29927CVE-2025-51683CVE-2025-53887CVE-2025-57231CVE-2026-0561CVE-2026-0650CVE-2026-0702CVE-2026-0743CVE-2026-0768CVE-2026-11801CVE-2026-1281CVE-2026-12898CVE-2026-18577CVE-2026-18963CVE-2026-19092CVE-2026-19632CVE-2026-2113CVE-2026-21875CVE-2026-23491CVE-2026-23536CVE-2026-23693CVE-2026-26265CVE-2026-27454CVE-2026-27960CVE-2026-28141CVE-2026-28411CVE-2026-29962CVE-2026-29963CVE-2026-30849CVE-2026-32475CVE-2026-33017CVE-2026-34234CVE-2026-41042CVE-2026-41452CVE-2026-41456CVE-2026-41679CVE-2026-41948CVE-2026-42221CVE-2026-4257CVE-2026-42596CVE-2026-42878CVE-2026-44177CVE-2026-44343CVE-2026-48558CVE-2026-53595CVE-2026-55040CVE-2026-55229CVE-2026-5524CVE-2026-5562CVE-2026-56292CVE-2026-57582CVE-2026-58123CVE-2026-58191CVE-2026-59177CVE-2026-59509CVE-2026-59726CVE-2026-60105CVE-2026-61511CVE-2026-61736CVE-2026-62382CVE-2026-65761CVE-2026-72898CVE-2026-73034CVE-2026-73570CVE-2026-7467CVE-2026-76904CVE-2026-77806CVE-2026-81199CVE-2026-81578CVE-2026-82222CVE-2026-82329CVE-2026-83548CVE-2026-8467CVE-2026-85200CVE-2026-85706CVE-2026-86206CVE-2026-86207CVE-2026-86426CVE-2026-87820CVE-2026-88062CVE-2026-9133CVE-2026-9586
Separate evidence group
Original

Exploit tooling coverage expanded for 10 CVEs

ProjectDiscovery nuclei-templates added or materially changed exploit-oriented artifacts covering 10 CVEs. This establishes public tooling availability; it does not establish exploitation in the wild or successful execution.

CVE-2017-7504CVE-2019-11043CVE-2020-10221CVE-2023-25157CVE-2024-1708CVE-2026-18963CVE-2026-23491CVE-2026-23536CVE-2026-40217CVE-2026-76904
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score59.5vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction19.96 / 20
Exploit availability7.5 / 15
Source independence0 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
8.7 · HIGH
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
CWE
CWE-120, CWE-787
CPE records
64
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.