Critical PHP SOAP Extension Vulnerabilities Enable Remote Code Execution

📰 Dev.to · BeyondMachines

PHP released emergency updates to fix five vulnerabilities, including two critical use-after-free flaws (CVE-2026-6722 and CVE-2026-7261) that allow unauthenticated remote code execution via the SOAP extension.

Published 13 May 2026
Read full article → ← Back to Reads