CVE-2026-6722 (matched: php)

  • Sunday, 26th July, 2026
  • 04:02am

A security flaw has been identified in specific versions of PHP, the software that powers most dynamic websites and web applications. The affected versions are all 8.2 releases older than 8.2.31, all 8.3 releases older than 8.3.31, all 8.4 releases older than 8.4.21, and all 8.5 releases older than 8.5.6. The issue is a flaw in PHP's SOAP extension, a tool used to handle certain types of structured web data exchanges. It stems from a memory handling error that can be triggered when a specially crafted SOAP request is sent to a site running one of the affected PHP versions. If exploited, this error allows an attacker who can send a custom SOAP request to your site to run unauthorized, malicious code on the server that hosts your site.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-6722

« Back