CVE-2026-6722Patch(php / php)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch php php systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.

2.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416CWE-825

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • php

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 30 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 17 signals
  • Technical details provided in 20 signals
  • Disclosure: 10 classified signals
  • General: 3 classified signals
  • Peaked 6d ago at 7 mentions (2026-05-12); latest day: 3
  • 30 total mentions across 9 days

Affected systems

Vendors
Products
php

Deep dive

Activity timeline30 mentions / 9d
02457Mentions · 2026-05-10: 3Mentions · 2026-05-11: 4Mentions · 2026-05-12: 7Mentions · 2026-05-13: 5Mentions · 2026-05-14: 1Mentions · 2026-05-17: 4Mentions · 2026-05-18: 2Mentions · 2026-06-18: 1Mentions · 2026-06-23: 3PoC Mentioned / Linked · 2026-05-13: 1Patch / Workaround · 2026-05-11: 3Patch / Workaround · 2026-05-12: 5Patch / Workaround · 2026-05-13: 4Patch / Workaround · 2026-05-17: 3Patch / Workaround · 2026-06-18: 1Patch / Workaround · 2026-06-23: 1Technical Details · 2026-05-10: 3Technical Details · 2026-05-11: 4Technical Details · 2026-05-12: 2Technical Details · 2026-05-13: 2Technical Details · 2026-05-14: 1Technical Details · 2026-05-17: 3Technical Details · 2026-05-18: 1Technical Details · 2026-06-18: 1Technical Details · 2026-06-23: 305-1005-1105-1205-1305-1405-1705-1806-1806-23
Signal classification4 categories
Patch
1653.3%
Disclosure
1033.3%
General
310.0%
PoC
13.3%
Referenced assets22 URLs
Classification over time
DateTotalLabels
2026-05-103
Disclosure2General1
2026-05-114
Disclosure2Patch2
2026-05-127
Disclosure2Patch5
2026-05-135
Patch4PoC1
2026-05-141
Disclosure1
2026-05-174
General1Patch3
2026-05-182
Disclosure1General1
2026-06-181
Patch1
2026-06-233
Disclosure2Patch1
Full discourse20 posts
  • Welsh ICP Conviction 🏴󠁧󠁢󠁷󠁬󠁳󠁿🏉@ICPLEGEND1966
    Disclosure

    🚨 PHP SOAP RCE IS ANOTHER REMINDER WHY OLD INTERNET INFRASTRUCTURE IS BREAKING — AND WHY $ICP BY @dfinity MATTERS ♾️ Another serious server-side vulnerability has landed. This time it is PHP. The critical issue is CVE-2026-6722, a use-after-free vulnerability in the PHP SOAP extension. The risk is not theoretical. A crafted SOAP request can abuse memory handling inside PHP’s XML / SOAP processing and potentially lead to remote code execution. That means a vulnerable server can move from “running an old component” to full compromise. The affected PHP versions are before: • PHP 8.2.31 • PHP 8.3.31 • PHP 8.4.21 • PHP 8.5.6 The PHP changelog also confirms related fixes for: • CVE-2026-6722 — stale SOAP reference / use-after-free • CVE-2026-7261 — SOAP use-after-free after header parsing failure • CVE-2026-7262 — broken Apache map NULL check • Other fixes affecting PHP standard / string handling components This is the same old internet problem. Centralized servers. Legacy runtimes. Patch windows. Exposed endpoints. Misconfigured services. Forgotten extensions. Memory corruption. Emergency updates. Attackers scanning before admins patch. And this is exactly why infrastructure matters. $ICP by @dfinity is not just another blockchain. It is building a different internet architecture where applications can run as canister smart contracts with: • Backend logic on-chain • Frontend assets served on-chain • Data stored on-chain • Identity handled without passwords through Internet Identity • Users not needing gas fees because of reverse gas • Reduced dependence on centralized web servers, exposed APIs, and traditional cloud stacks That does not mean every bug disappears. But it does mean the architecture changes. With ICP, applications are not forced into the same Web2 pattern of: PHP server → database → cloud VM → API keys → DNS → CDN → third-party identity → centralized hosting. That old stack is where many real-world compromises keep happening. PHP SOAP RCE is not just a PHP issue. It is a warning about the fragility of the internet stack most applications still depend on. Crypto keeps arguing about memes, bridges, and token speculation. Meanwhile, the real battle is bigger: Who can build secure, verifiable, tamper-resistant internet infrastructure? That is where $ICP by @dfinity stands apart. Not hype. Not another L1 copy. Not just transactions. A real attempt to rebuild the application layer of the internet itself. The more AI, finance, identity, and enterprise systems move online, the more this matters. Old servers are becoming attack surfaces. ICP is building toward a world where the application itself can become part of the blockchain security model. That is the difference. That is the thesis. That is why I keep saying most people are not bullish enough on $ICP. ♾️ $ICP by @dfinity is not chasing the old internet. It is replacing the broken parts. #ICP #InternetComputer #DFINITY #CyberSecurity #Web3 #Blockchain #OnchainCloud #AI #InfoSec #Crypto Support my independent $ICP research and content: ICP address: 1e672d038cebc619d93186418fa98f6499dbdb9cfdfac54f366c61a4a4ee4362

    Post summary

    The post announces the discovery of a critical PHP SOAP use‑after‑free RCE (CVE‑2026‑6722), highlights its impact and affected PHP versions, but gives no PoC, exploit or patch details.

    040231647
    1.5K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    PHP releases urgent security patches for a 9.5 severity RCE in the SOAP extension and a PHP-FPM XSS flaw. Update to 8.2.31, 8.3.31, 8.4.21, or 8.5.6 now! #PHP #InfoSec #RCE #VulnerabilityAlert #PatchNow #DevOps #WebSecurity #CVE #SysAdmin #ServerSecurity https://securityonline.info/php-security-patch-rce-soap-cve-2026-6722/ https://t.co/fZfek2Vul9

    Post summary

    PHP announces urgent patches for a high‑severity RCE in the SOAP extension and an XSS flaw, urging updates to the latest minor releases.

    02081653
    12.5K followersView on X
  • AI Heartland@peaks2314
    Patch

    🚨 PHP SOAP拡張に深刻なUse-After-Free(CVE-2026-6722)が見つかった。 CVSS 9.5(Critical) PHP 8.2〜8.5系が対象で、攻撃者がSOAPリクエスト本文を制御できれば認証不要・ユーザー操作不要でRCEに至る恐れがある 昔の決済プラグインやERP連携ライブラリが内部でSOAPを叩いているケースが多い。 ▶ まず確認:php -v と php -m | grep soap ▶ 修正版:8.2.31 / 8.3.31 / 8.4.21 / 8.5.6(2026年5月7日リリース済み) 脆弱性の根本原因・パッチ適用手順・Docker対応・侵害痕跡の見方まで詳しく解説しました。 https://ai-heartland.com/news/news-php-cve-2026-6722-rce-soap/ #PHP #セキュリティ #CVE #WebSecurity

    Post summary

    The post alerts about CVE‑2026‑6722, providing vulnerability details and patch versions for PHP 8.2‑8.5, but does not report active exploitation or a PoC.

    00062249
    3.4K followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Patch

    「PHP」に複数の「クリティカル」脆弱性 - アップデートで解消:Security NEXT https://www.security-next.com/184498 "「CVE-2026-6722」は、「PHP」でSOAPクライアントやサーバ機能を提供するエクステンションのリクエスト解析処理に起因する「Use After Free」の脆弱性…リモートよりコードを実行されるおそれ"

    Post summary

    The post highlights several critical PHP vulnerabilities, notably CVE‑2026‑6722, a Use After Free issue that could enable remote code execution, and indicates that applying the available update will mitigate the risk.

    00111292
    3.5K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    PHP SOAP Extension の脆弱性 CVE-2026-6722 などが FIX:リモートコード実行の恐れ https://iototsecnews.jp/2026/05/11/php-soap-extension-flaw-could-let-attackers-execute-code-remotely/ PHP の SOAP エクステンションなどで見つかった、深刻な脆弱性について解説する記事です。問題の原因は、複雑な XML データを解析する際のメモリ管理不備や、入力値の検証不足にあります。特に CVE-2026-6722 は、データの参照カウントを正しく制御できなかったことで、解放済みのメモリを悪用して任意のプログラムを実行される (RCE) 恐れがあります。この他にも、サーバを停止させる DoS 攻撃や情報漏洩につながる脆弱性も複数特定されました。ご利用のチームは、ご注意ください。 #CVE20266104 #CVE20266722 #CVE20267258 #CVE20267261 #CVE20267262 #PHP #SOAPExtension #Vulnerability

    Post summary

    The article announces newly discovered PHP SOAP Extension vulnerabilities, notably CVE‑2026‑6722, explaining memory‑management flaws that could lead to RCE, DoS, and data leaks. It provides technical details but no PoC, exploit, or patch information.

    01001150
    489 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php83 Module Update 8.3.31-1 https://kusanagi.tokyo/en/releases/24567/ KUSANAGI 9 modules have been updated. The updated modules are as follows: php 8.3.31-1 This update includes support for vulnerability(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261,...

    Post summary

    The message announces a module update that applies patches for several CVEs, without providing any PoC, exploit code, or evidence of active exploitation.

    010101.1K
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php83 モジュール更新情報 8.3.31-1 https://kusanagi.tokyo/releases/24566/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 php 8.3.31-1 この更新には脆弱性(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261, CVE-2026-7262, CVE-2026-7568, CVE-2...

    Post summary

    This announcement informs users of a KUSANAGI module update (php 8.3.31‑1) that includes fixes for several listed CVEs.

    01010104
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php83 モジュール更新情報 8.3.31-1.el9 https://kusanagi.tokyo/releases/24559/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 php 8.3.31-1.el9 この更新には脆弱性(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261, CVE-2026-7262, CVE-2026-756...

    Post summary

    The release notes announce a KUSANAGI 9 PHP module update (8.3.31‑1.el9) that patches multiple CVEs, including CVE‑2026‑6735, CVE‑2026‑7259, and others.

    0101099
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php82 モジュール更新情報 8.2.31-1.el9 https://kusanagi.tokyo/releases/24522/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 php 8.2.31-1.el9 この更新には脆弱性(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261, CVE-2026-7262, CVE-2026-756...

    Post summary

    Kusanagi PHP 8.2.31-1.el9 update released, containing patches for multiple CVEs. No evidence of PoC, exploit, or active exploitation reported.

    0101094
    200 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    [1] Security Online - Critical 9.5 Severity: PHP SOAP Extension Flaw Enables Remote Code Execution A critical Use-After-Free (UAF) flaw in PHP's SOAP extension (CVE-2026-6722, CVSS 9.5) allows unauthenticated attackers to execute arbitrary code on any vulnerable server…

    Post summary

    The text announces a critical Use‑After‑Free flaw (CVE‑2026‑6722) in PHP’s SOAP extension with a CVSS score of 9.5 that allows unauthenticated remote code execution. No PoC, exploit, patch, or active exploitation is mentioned.

    1000034
    295 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    A critical Use-After-Free (UAF) flaw in PHP's SOAP extension (CVE-2026-6722, CVSS 9.5) allows unauthenticated attackers to execute arbitrary code on any vulnerable server via specially crafted SOAP requests. Immediate patching to PHP 8.2.31, 8.3.31, 8.4.21, or 8.5.6+ is…

    Post summary

    The post announces a critical UAF vulnerability in PHP’s SOAP extension, provides its CVSS score, and lists exact patch versions, but offers no PoC or exploit details.

    1000036
    295 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    6722, CVSS — Critical PHP SOAP Extension Vulnerability Enables Unauthenticated Remote Code Execution — CVE-2026-6722. A critical Use-After-Free (UAF) flaw in PHP's SOAP extension (CVE-2026-6722, CVSS 9.5) allows unauthenticated attackers to execute arbitrary code on any…

    Post summary

    The text announces a critical PHP SOAP extension vulnerability (CVE‑2026‑6722) characterized by a Use‑After‑Free bug that enables unauthenticated remote code execution, but it provides no PoC, exploit, patch, or evidence of active exploitation.

    1000043
    295 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en productos PHP ❗ CVE-2026-6722 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-php/ https://t.co/YzUspsxRBh

    Post summary

    The tweet announces CVE‑2026‑6722, a vulnerability in PHP products, and directs readers to a URL for more details, but provides no technical data, PoC, exploit, or patch information.

    00010173
    6.7K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE-2026-6722: 🚨 PHP SOAP RCE IS ANOTHER REMINDER WHY OLD INTERNET INFRASTRUCTURE IS BREAKING — AND WHY $ICP BY @dfinity MATTERS ♾️ Another serious server-side vulnerability has landed. This time it is PHP. The critical issue is CVE-2026-6722, a use-after-free…

    Post summary

    The post announces CVE‑2026‑6722 as a use‑after‑free vulnerability in PHP SOAP but does not provide any proof‑of‑concept, exploitation details, or patch information.

    1000080
    226 followersView on X
  • Uehara Hide@o6asan
    Disclosure

    #PHP 8.5.5 → 8.5.6 CVE-2026-6722 とかいろいろアナウンスされてたし。 ところで、今回から、 gobject-2.dll も同梱になった。 https://www.php.net/ChangeLog-8.php#8.5.6

    Post summary

    The post announces that PHP 8.5.6 includes new releases and mentions CVE-2026-6722 among other announced CVEs, but provides no technical details or exploit information.

    0000191
    19 followersView on X
  • Vignesh_Pravin@VigneshVic23698
    Disclosure

    PHP ext-soap Use-After-Free Flaw Enables RCE – CVE-2026-6722 https://thecybrdef.com/php-ext-soap-use-after-free-flaw-enables-rce-cve-2026-6722/ #CVE202642569 #Cyberupdate #Cybersecuirty

    Post summary

    Announcement of a new PHP ext‑soap Use‑After‑Free flaw (CVE‑2026‑6722) that allows remote code execution.

    0000171
    2 followersView on X
  • Falcon Internet@falconinet
    Patch

    PHP SOAP Extension RCE (CVE-2026-6722): CVSS 9.8, Patch Now https://www.falconinternet.net/blog/php-soap-rce-cve-2026-6722-patch-now?ref=x #Security #WebHosting https://t.co/I49m0eLEgq

    Post summary

    The tweet announces CVE-2026-6722, a critical remote code execution flaw in PHP’s SOAP extension, and urges users to apply the available patch.

    0000035
    18 followersView on X
  • Virus Myths!@virusmyths
    Patch

    [긴급] PHP 원격 코드 실행(RCE) 및 Use-After-Free(UAF) 취약점(CVE-2026-6722) 패치 설치 권고 (출처 : Virus My.. | 블로그) https://m.blog.naver.com/nologout/224283177900

    Post summary

    The blog advises installing a patch for PHP vulnerability CVE‑2026‑6722, describing it as an RCE and UAF issue, with no evidence of current exploitation or PoC.

    0000058
    21 followersView on X
  • てもさわ@6LR61YXJ
    Patch

    CVE-2026-6722 remiはphp7.4とかでも対応してた。ありがたい話だよ

    Post summary

    The text indicates that CVE-2026-6722 has been fixed in Remi's PHP 7.4 package, showing that a patch is available.

    0000065
    362 followersView on X
  • PinakaHQ@pinakahq
    PoC

    CVE-2026-6722: PHP SOAP Extension Use-After-Free RCE https://pinaka.sh/blog/cve-2026-6722-php-soap-use-after-free-rce PHP issue - Identify, make PoC, ASK THEM TO FIX IT ASAP!! #ai #aisecurity #cybersecurity #attack #zeroday

    Post summary

    The post links to a blog containing a PoC for CVE-2026-6722, a PHP SOAP Extension use‑after‑free vulnerability that enables remote code execution, and urges a swift fix.

    0000019
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appphpphp---

Explore more