CVE-2026-6722 (matched: php)

  • Saturday, 25th July, 2026
  • 22:03pm

A security flaw, tracked as CVE-2026-6722, has been identified in specific versions of PHP, the programming language that powers many interactive website features. The issue affects PHP’s SOAP extension, a tool used for exchanging data between different web services. The flaw can be exploited by an attacker who can send specially crafted requests to a website running an affected PHP version. If successfully exploited, this could allow the attacker to run unauthorized code on the server hosting the website. This may give the attacker full control of the site, let them steal sensitive data stored on the server, or make unapproved changes to website content. The affected PHP versions are 8.2 releases older than 8.2.31, 8.3 releases older than 8.3.31, 8.4 releases older than 8.4.21, and 8.5 releases older than 8.5.6.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-6722

« Back