CVE-2017-9841 — exploited in the wild
Exploitation observed by OffSeq honeypot sensors · last 30 days · last seen 16 hours ago · first observed 2026-08-16 (29 days ago)
Listed in CISA's Known Exploited Vulnerabilities catalog and still under active attack against OffSeq honeypot decoys.
About CVE-2017-9841
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.
CWE-94
OffSeq's global honeypot fleet recorded 1,127 exploitation attempts against CVE-2017-9841 from 87 distinct source IPs in the last 30 days — direct in-the-wild telemetry: every hit is a real attacker probing a decoy, not a scan of a vulnerability database. It is also present on 1 internet-exposed hosts OffSeq tracked in the last 30 days.
Top attacking countries
- France442
- Morocco396
- United States160
- Poland49
- The Netherlands46
- Indonesia8
- Italy8
- Mexico3
- Japan3
- Belgium2
- South Korea2
- Canada2