Critical PHP SOAP Extension Flaw Enables Remote Code Execution Attacks
ID: 9c19a235-4bf9-5afb-b649-3416ceb14fd6
STIX ID: report--9c19a235-4bf9-5afb-b649-3416ceb14fd6
Feed Name: Cyber Press
Threat Score
A set of memory-safety vulnerabilities in PHP—including a high-severity Use-After-Free in the SOAP extension (CVE-2026-6722) enabling reliable remote code execution, plus additional UAF, NULL-dereference, and out-of-bounds read issues—affect PHP releases prior to 8.2.31, 8.3.31, 8.4.21, and 8.5.6; administrators are urged to install the patched versions immediately to prevent RCE and DoS risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
