A security flaw, tracked as CVE-2026-6722, has been identified in specific older versions of PHP, the software that powers most dynamic websites. The flaw affects PHP 8.2 versions older than 8.2.31, 8.3 versions older than 8.3.31, 8.4 versions older than 8.4.21, and 8.5 versions older than 8.5.6, and exists in PHP's SOAP extension, a tool used to process certain types of data requests sent to websites.
The bug can be triggered by a specially crafted SOAP request sent to a site running an affected PHP version. An attacker with the ability to send this type of request can exploit the flaw to run unauthorized code on your hosting environment. If successfully exploited, this could let bad actors access your website data, alter your site's content, or misuse your hosting resources for harmful activity.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-6722