CVE-2026-6722 (matched: php)

  • Friday, 24th July, 2026
  • 22:03pm

A security vulnerability has been identified in specific older versions of PHP, the software used to run many dynamic websites. The affected versions are PHP 8.2 releases older than 8.2.31, 8.3 releases older than 8.3.31, 8.4 releases older than 8.4.21, and 8.5 releases older than 8.5.6.

The flaw exists in PHP's SOAP extension, a component used for certain types of web service communication. If an attacker can send a specially crafted request to a website running one of the affected PHP versions, they could exploit this vulnerability to gain full control of the server hosting the site. This could allow them to access your site's data, alter your site's content, or steal information from you and your site's visitors.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-6722

« Back