logo

PHP SOAP Extension Flaw Could Let Attackers Execute Code Remotely

ID: 765b3396-243e-563c-9f9b-512d90053dfd

STIX ID: report--765b3396-243e-563c-9f9b-512d90053dfd

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: Divya

...
...

Multiple PHP vulnerabilities were disclosed, led by CVE-2026-6722 — a high-severity Use-After-Free in the SOAP extension that can be weaponized for reliable remote code execution via crafted XML. Several additional moderate flaws (another UAF in session persistence, a NULL pointer dereference in Apache Map decoding, and out-of-bounds reads in urldecode() and mb_convert_encoding()) affect PHP versions prior to 8.2.31, 8.3.31, 8.4.21, and 8.5.6; administrators are advised to apply the provided patches immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.