logo

Critical 9.5 Severity: PHP SOAP Extension Flaw Enables Remote Code Execution

ID: 9ee3a823-124a-5124-843b-437400b23e9a

STIX ID: report--9ee3a823-124a-5124-843b-437400b23e9a

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: Ddos

...
...

This advisory details multiple security vulnerabilities across PHP versions (including 8.2, 8.3, 8.4, and 8.5), highlighting a critical SOAP extension use-after-free (CVE-2026-6722, CVSS 9.5) that can lead to remote code execution, an XSS on the PHP-FPM status page (CVE-2026-6735, CVSS 7.3), and several lesser but impactful bugs causing crashes or denial-of-service; administrators are urged to update to the patched releases (8.2.31, 8.3.31, 8.4.21, or 8.5.6) immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.