Critical PHP SOAP Extension Vulnerabilities Enables Remote Code Execution Attacks
ID: 89412895-5e2b-55e1-8b62-9e3b790dc630
STIX ID: report--89412895-5e2b-55e1-8b62-9e3b790dc630
Feed Name: cybersecurityNews.com
Threat Score
A cluster of serious PHP vulnerabilities—most notably CVE-2026-6722, an unauthenticated use-after-free in the SOAP extension enabling remote code execution—has been disclosed. Additional flaws include session-related UAF, NULL-dereference DoS, an urldecode out-of-bounds read, and an mbstring buffer overrun affecting multiple supported PHP branches; maintainers have released patches in PHP 8.2.31, 8.3.31, 8.4.21, and 8.5.6 and administrators are urged to update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
