Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.
Published: 2019-09-05
Attackers are leveraging a vulnerability patched nearly three years ago to target Drupal sites. Background On September 4, Drupal published PSA-2019-09-04, a public service announcement (PSA) for a vulnerability in a third-party library in a Drupal module that’s being actively exploited in the wild.
https://www.oracle.com/security-alerts/cpuoct2021.html
https://security.gentoo.org/glsa/201711-15
https://github.com/sebastianbergmann/phpunit/pull/1956
https://github.com/sebastianbergmann/phpunit/commit/284a69fb88a2d0845d23f42974a583d8f59bf5a5
http://web.archive.org/web/20170701212357/http://phpunit.vulnbusters.com/
https://blog.talosintelligence.com/year-in-review-vulnerabilities-old-and-new-and-something-react2/
https://www.labs.greynoise.io/grimoire/2026-03-23-bucklog-k8s/
https://www.helpnetsecurity.com/2026/03/18/government-agencies-cyberattack-campaigns-volume/
https://www.infosecurity-magazine.com/news/php-servers-and-iot-devices-cyber/
https://thehackernews.com/2025/10/experts-reports-sharp-increase-in.html
https://therecord.media/cryptomining-group-kinsing-hits-russia
https://isc.sans.edu/diary/rss/31528
https://www.infosecurity-magazine.com/news/androxgh0st-botnet-adopts-mozi/
https://hackread.com/androxgh0st-botnet-integrate-mozi-iot-vulnerabilities/
https://isc.sans.edu/diary/rss/31086
https://www.akamai.com/blog/security-research/2024-redtail-cryptominer-pan-os-cve-exploit
https://blogs.juniper.net/en-us/security/shielding-networks-against-androxgh0st
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-016a
https://blog.aquasec.com/loony-tunables-vulnerability-exploited-by-kinsing
https://github.com/brian-mitchell-sec/http-bait
https://github.com/onionsgun/cve
https://github.com/fDarkShadow/noctis
https://github.com/flags-alt/abyss-c2
https://github.com/MR-LeonardoGomes/CVE-2017-9841
https://github.com/wintra/CVE-Analysis-Incident-Response
https://github.com/Habibullah1101/PHPUnit-GoScan
https://github.com/drcrypterdotru/PHPUnit-GoScan
https://github.com/imthenachoman/How-To-Secure-A-Linux-Server
https://github.com/giorgimakasarashvili/WEB-PEN-CVE
https://github.com/Yucaerin/laravel
https://github.com/MrG3P5/CVE-2017-9841
https://github.com/MadExploits/PHPunit-Exploit
https://github.com/mileticluka1/eval-stdin
https://github.com/jax7sec/CVE-2017-9841
https://github.com/p1ckzi/CVE-2017-9841
https://github.com/advisories/GHSA-r7c9-c69m-rph8
https://github.com/ludy-dev/PHPUnit_eval-stdin_RCE
https://github.com/RandomRobbieBF/phpunit-brute
https://github.com/mbrasile/CVE-2017-9841
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-9841
Published: 2017-06-27
Updated: 2026-06-17
Known Exploited Vulnerability (KEV)
Base Score: 7.5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
Severity: High
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
EPSS: 0.99999
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability Being Monitored