A security flaw has been identified in specific versions of PHP, the software that powers most dynamic websites. The issue impacts PHP 8.2 versions older than 8.2.31, 8.3 versions older than 8.3.31, 8.4 versions older than 8.4.21, and 8.5 versions older than 8.5.6, and is located in PHP's SOAP extension, a feature used for certain types of web service data exchanges.
The flaw stems from a memory handling error in the SOAP extension. If an attacker can send a specially crafted SOAP request to your website, they can exploit this error to run unauthorized code on your hosting server. This could let them access data stored on your site, change your website's content, or take other unapproved actions related to your hosting account.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-6722