logo

Critical PHP SOAP Extension Vulnerabilities Enables Remote Code Execution Attacks

ID: 89412895-5e2b-55e1-8b62-9e3b790dc630

STIX ID: report--89412895-5e2b-55e1-8b62-9e3b790dc630

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Abinaya

...
...

A cluster of serious PHP vulnerabilities—most notably CVE-2026-6722, an unauthenticated use-after-free in the SOAP extension enabling remote code execution—has been disclosed. Additional flaws include session-related UAF, NULL-dereference DoS, an urldecode out-of-bounds read, and an mbstring buffer overrun affecting multiple supported PHP branches; maintainers have released patches in PHP 8.2.31, 8.3.31, 8.4.21, and 8.5.6 and administrators are urged to update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.