CentOS Linux 7.9 [CIQ] Security Update: php / php-bcmath / php-cli / php-common / php-dba / php-debuginfo / etc Multiple Vulnerabilities (ciqsa-2026_0728)

critical Nessus Plugin ID 355689

Synopsis

The CentOS Linux host is missing one or more security updates.

Description

The CentOS Linux 7.9 host has packages installed that are affected by multiple vulnerabilities as referenced in the CIQ ciqsa-2026_0728 advisory.

This advisory aggregates security fixes for the php SRPM in CIQ CentOS Bridge 7.9. It addresses 65 CVEs:
CVE-2014-0185, CVE-2014-3981, CVE-2014-9427, CVE-2014-9767, CVE-2015-0235, and 60 more.

Tenable has extracted the preceding description block directly from the CIQ security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages based on the guidance in CIQ advisory ciqsa-2026_0728.

See Also

https://github.com/ctrliq/advisories

http://www.nessus.org/u?0305c5c8

http://www.nessus.org/u?07f03d52

http://www.nessus.org/u?0ba8de30

http://www.nessus.org/u?0d372b12

http://www.nessus.org/u?10a7c9f5

http://www.nessus.org/u?12f386d1

http://www.nessus.org/u?157593c0

http://www.nessus.org/u?1a77e2cc

http://www.nessus.org/u?2297d085

http://www.nessus.org/u?23b1ab5d

http://www.nessus.org/u?24bc0e4d

http://www.nessus.org/u?275f0e7a

http://www.nessus.org/u?28972e40

http://www.nessus.org/u?2a67f504

http://www.nessus.org/u?2b137dcf

http://www.nessus.org/u?2b534172

http://www.nessus.org/u?2c2c3939

http://www.nessus.org/u?347ff1f3

http://www.nessus.org/u?35fdfc90

http://www.nessus.org/u?38623467

http://www.nessus.org/u?3913ed0e

http://www.nessus.org/u?4157372a

http://www.nessus.org/u?4449deb0

http://www.nessus.org/u?469058cd

http://www.nessus.org/u?4908a0c2

http://www.nessus.org/u?4afe0d87

http://www.nessus.org/u?50ed76fa

http://www.nessus.org/u?522d4e5a

http://www.nessus.org/u?5b0b81a6

http://www.nessus.org/u?5c93406d

http://www.nessus.org/u?5e6d8db8

http://www.nessus.org/u?70986520

http://www.nessus.org/u?718b1aa0

http://www.nessus.org/u?73b943b7

http://www.nessus.org/u?79533d42

http://www.nessus.org/u?8584516c

http://www.nessus.org/u?953c872d

http://www.nessus.org/u?972c60dd

http://www.nessus.org/u?a544da06

http://www.nessus.org/u?b01f87b3

http://www.nessus.org/u?b33c14e3

http://www.nessus.org/u?b3bc1b79

http://www.nessus.org/u?b477f1af

http://www.nessus.org/u?b5b4fd7b

http://www.nessus.org/u?b63ca626

http://www.nessus.org/u?b722e50a

http://www.nessus.org/u?b7bf6ec0

http://www.nessus.org/u?bc4cdfa5

http://www.nessus.org/u?bed28ed9

http://www.nessus.org/u?bf0d9168

http://www.nessus.org/u?c04c95de

http://www.nessus.org/u?c229a8cd

http://www.nessus.org/u?cac72a74

http://www.nessus.org/u?cbc071dd

http://www.nessus.org/u?cd86ccde

http://www.nessus.org/u?cdb745fc

http://www.nessus.org/u?d2f9c0b6

http://www.nessus.org/u?d41599ec

http://www.nessus.org/u?d9f51d12

http://www.nessus.org/u?e4a7f36a

http://www.nessus.org/u?eb49177c

http://www.nessus.org/u?efe88dc0

http://www.nessus.org/u?f8d9e1be

http://www.nessus.org/u?fb30faa9

http://www.nessus.org/u?fc95cd5c

http://www.nessus.org/u?fdfd36b3

Plugin Details

Severity: Critical

ID: 355689

File Name: ciq_centos_7_9_ciqsa-2026_0728.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 10/1/2026

Updated: 10/1/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.5

Percentile: 99.87

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2015-5589

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 9.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

CVSS Score Source: CVE-2019-9020

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/CentOS/release, Host/CentOS/rpm-list, Host/OS/extended-third-party

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/1/2026

Vulnerability Publication Date: 4/29/2014

Reference Information

CVE: CVE-2014-0185, CVE-2014-3981, CVE-2014-9427, CVE-2014-9767, CVE-2015-0235, CVE-2015-1352, CVE-2015-2305, CVE-2015-2325, CVE-2015-2326, CVE-2015-2331, CVE-2015-3152, CVE-2015-3411, CVE-2015-3412, CVE-2015-3414, CVE-2015-3415, CVE-2015-3416, CVE-2015-4147, CVE-2015-4148, CVE-2015-4598, CVE-2015-4599, CVE-2015-4604, CVE-2015-4605, CVE-2015-4642, CVE-2015-4643, CVE-2015-4644, CVE-2015-5589, CVE-2015-5590, CVE-2015-6831, CVE-2015-6832, CVE-2015-6833, CVE-2015-6834, CVE-2015-6835, CVE-2015-6836, CVE-2015-6837, CVE-2015-6838, CVE-2015-8867, CVE-2016-4070, CVE-2016-4342, CVE-2016-4343, CVE-2016-6290, CVE-2016-6295, CVE-2016-6296, CVE-2016-6297, CVE-2016-7125, CVE-2016-7126, CVE-2016-7127, CVE-2016-7129, CVE-2016-7130, CVE-2016-7131, CVE-2016-7132, CVE-2016-7416, CVE-2016-7417, CVE-2016-7418, CVE-2016-7480, CVE-2016-8670, CVE-2017-5340, CVE-2019-11048, CVE-2019-19203, CVE-2019-19204, CVE-2019-9020, CVE-2019-9637, CVE-2020-26159, CVE-2020-7062, CVE-2021-21702, CVE-2023-0568