Menu

Post image 1
Post image 2
1 / 2
0

Critical PHP SOAP Extension Vulnerabilities Enable Remote Code Execution

DEV Community·BeyondMachines·20 days ago
#iNO2L9Gf
Reading 0:00
15s threshold
Cover image for Critical PHP SOAP Extension Vulnerabilities Enable Remote Code Execution

Summary

PHP released emergency updates to fix five vulnerabilities, including two critical use-after-free flaws (CVE-2026-6722 and CVE-2026-7261) that allow unauthenticated remote code execution via the SOAP extension.

Take Action:

If you run PHP on your web servers, update immediately to version 8.2.31, 8.3.31, 8.4.21, or 8.5.6. If you can't patch right away, disable the SOAP extension as a temporary measure until the update is applied.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Read More