A security vulnerability has been identified in specific older versions of PHP, the core software that runs most dynamic, interactive websites. The affected versions are PHP 8.2 releases older than 8.2.31, 8.3 releases older than 8.3.31, 8.4 releases older than 8.4.21, and 8.5 releases older than 8.5.6.
The flaw exists in PHP's SOAP extension, a feature used to process requests from other apps, services, and websites. An attacker who can send a specially crafted SOAP request to a site running an affected PHP version can exploit this issue to run unauthorized code on your website's server. This could let them steal your site's data, change your website's content, or access other parts of your hosting account without permission.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-6722