logo

Critical PHP SOAP Extension Flaw Enables Remote Code Execution Attacks

ID: 9c19a235-4bf9-5afb-b649-3416ceb14fd6

STIX ID: report--9c19a235-4bf9-5afb-b649-3416ceb14fd6

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: AnuPriya

...
...

A set of memory-safety vulnerabilities in PHP—including a high-severity Use-After-Free in the SOAP extension (CVE-2026-6722) enabling reliable remote code execution, plus additional UAF, NULL-dereference, and out-of-bounds read issues—affect PHP releases prior to 8.2.31, 8.3.31, 8.4.21, and 8.5.6; administrators are urged to install the patched versions immediately to prevent RCE and DoS risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.