A security flaw has been found in multiple versions of PHP, the software that powers most interactive, dynamic websites. The affected versions are all releases of PHP 8.2 older than 8.2.31, 8.3 older than 8.3.31, 8.4 older than 8.4.21, and 8.5 older than 8.5.6. The issue impacts sites that use PHP's SOAP server feature with session persistence enabled for these types of requests. When a SOAP request returns an error, the system incorrectly handles the saved request data, creating a broken reference to data that has already been cleared from the system. This can lead to unexpected site crashes, exposure of sensitive site or user data, or corruption of stored information on your hosting account, impacting the reliability and security of your website.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-7261