The current version of PHP is 8.5.11 (as of 24/09/2026). patchletter checks the official source daily and emails you new releases.
Actively exploited vulnerabilities
The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. What CISA does not carry does not appear in this list — even where it is being exploited.
9.8 critical · over the network, without login · CISA deadline was 15 Apr 22
9.8 critical · over the network, without login · CISA deadline was 3 Jul 24
- CVE-2012-1823PHP-CGI Query String Parameter Vulnerability
9.8 critical · over the network, without login · CISA deadline was 15 Apr 22
Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.
BSI security advisories
Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.
- PHP: Mehrere Schwachstellen
WID-SEC-W-2026-3585 · 8 Oct
- PCRE (Perl Compatible Regular Expressions): Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit den Rechten des Dienstes
WID-SEC-W-2026-3766 · 7 Oct
- PHP: Mehrere Schwachstellen
WID-SEC-W-2026-2598 · 15 Sept
- PHP: Mehrere Schwachstellen ermöglichen Denial of Service
WID-SEC-W-2026-2186 · 7 Sept
- PHP: Mehrere Schwachstellen
WID-SEC-W-2023-1281 · 1 Sept
- PHP: Mehrere Schwachstellen
WID-SEC-W-2026-1433 · 30 Jul
- PHP: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff
WID-SEC-W-2026-1793 · 17 Jul
- PHP: Mehrere Schwachstellen
WID-SEC-W-2025-2887 · 15 Jun
PHP at a glance
PHP is the language behind a large share of the web (WordPress, TYPO3, Nextcloud and countless custom apps). The project ships a new minor version yearly, each maintained with bug and security fixes for a few years; security patches also cover bundled extensions.
For admins PHP is usually a runtime beneath a web application, whose requirements set the version. Apply security fixes promptly, and keep the end-of-life date of your minor version in view — running an unsupported PHP is a common, serious exposure. Multiple PHP versions often coexist (php-fpm pools); on updates, check the application and its extensions. Harden the configuration (disable risky functions, current settings) and keep the web-facing app patched too. Moving a major PHP version is a planned, testable step.
Support cycles (endoflife.date)
| Cycle | Latest version | Status |
|---|---|---|
| 8.5 | 8.5.11 | EOL 31 Dec 29 |
| 8.4 | 8.4.26 | EOL 31 Dec 28 |
| 8.3 | 8.3.35 | EOL 31 Dec 27 |
| 8.2 | 8.2.34 | EOL in 81 days |
| 8.1 | 8.1.34 | End of Life |
| 8.0 | 8.0.30 | End of Life |
| 7.4 | 7.4.33 | End of Life |
| 7.3 | 7.3.33 | End of Life |
Version history & changelog · as detected by patchletter
| Version | Channel | Date | Notes |
|---|---|---|---|
| 8.5.11 | STABLE | 24/09/2026 | – |
| 8.5.10 | STABLE | 27/08/2026 | – |
| 8.5.9 | STABLE | 30/07/2026 | – |
| 8.5.8 | STABLE | 02/07/2026 | – |
| 8.4.26 | STABLE | 24/09/2026 | – |
| 8.4.25 | STABLE | 27/08/2026 | – |
| 8.4.24 | STABLE | 30/07/2026 | – |
| 8.4.23 | STABLE | 02/07/2026 | – |
| 8.3.35 | STABLE | 24/09/2026 | – |
| 8.3.33 | STABLE | 30/07/2026 | – |
| 8.3.32 | STABLE | 02/07/2026 | – |
| 8.2.34 | STABLE | 24/09/2026 | – |
| 8.2.33 | STABLE | 30/07/2026 | – |
| 8.2.32 | STABLE | 02/07/2026 | – |
| 8.1.34 | STABLE | 18/12/2025 | – |
| 8.0.30 | STABLE | 03/08/2023 | – |
| 7.4.33 | STABLE | 03/11/2022 | – |
| 7.3.33 | STABLE | 18/11/2021 | – |
| 7.2.34 | STABLE | 01/10/2020 | – |
| 7.1.33 | STABLE | 24/10/2019 | – |
| 7.0.33 | STABLE | 10/01/2019 | – |
| 5.6.40 | STABLE | 10/01/2019 | – |
| 5.5.38 | STABLE | 21/07/2016 | – |
| 5.4.45 | STABLE | 03/09/2015 | – |
| 5.3.29 | STABLE | 14/08/2014 | – |
| 5.2.17 | STABLE | 06/01/2011 | – |
| 5.1.6 | STABLE | 24/08/2006 | – |
| 5.0.5 | STABLE | 05/09/2005 | – |
Frequently asked questions
- What is the latest version of PHP?
- PHP 8.5.11, released 24/09/2026. patchletter checks the vendor's official source daily for new releases.
- Where can I find the PHP release notes?
- The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
- How do I get notified about new PHP updates?
- Tick PHP off in the catalogue and leave your address. From then on new versions go out by email — one at a time, or bundled in the daily or weekly digest.
An email as soon as a new PHP version ships
We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The update email is free and ends with one click. Alerts about vulnerabilities and end of support are part of patchletter Pro.
Embed this badge
The badge shows the current PHP version and keeps it up to date. Anyone may embed it, no account needed.
[](https://patchletter.com/en/software/php)https://patchletter.com/badge/php.svgAlso available: ?v=eol (end of support) and ?v=cve (actively exploited).