A security vulnerability has been found in specific versions of PHP, the open-source software that powers the majority of dynamic websites on the internet. The affected versions include all 8.2 releases older than 8.2.31, all 8.3 releases older than 8.3.31, all 8.4 releases older than 8.4.21, and all 8.5 releases older than 8.5.6.
The flaw exists in the part of PHP that processes SOAP requests, a common format for web data exchanges. If an attacker can send a specially crafted SOAP request to a website running one of these affected PHP versions, they can exploit a memory handling error to run unauthorized code on the server that hosts the site.
This type of vulnerability could allow attackers to access, modify, or delete your site's content, or gain access to other data stored on the same hosting server.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-6722