A critical vulnerability CVE-2021-21703 has been identified in PHP-FPM, the FastCGI process manager included with the main PHP distribution since version 5.3. This vulnerability allows an unprivileged hosting user to execute code with root privileges. The issue manifests on servers using PHP-FPM for running PHP scripts, typically paired with Nginx. Researchers who discovered the issue were able to prepare a working exploit prototype.