A security vulnerability has been found in specific versions of PHP, the software that powers most dynamic websites and web applications including content management systems, user login tools, and interactive features. The flaw exists in PHP's SOAP extension, a component used for communication between different web services.
If your site runs one of the affected PHP versions, an attacker who can send a specially crafted request to your site could exploit this flaw. A successful attack would let the attacker take full control of your website and any data stored on it.
The impacted PHP versions are 8.2 releases older than 8.2.31, 8.3 releases older than 8.3.31, 8.4 releases older than 8.4.21, and 8.5 releases older than 8.5.6.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-6722