CVE-2026-7261Patch(php / php)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch php php systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • php

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 3 mentions (2026-05-12); latest day: 1
  • 10 total mentions across 5 days

Affected systems

Vendors
Products
php

Deep dive

Activity timeline10 mentions / 5d
01223Mentions · 2026-05-10: 2Mentions · 2026-05-12: 3Mentions · 2026-05-13: 3Mentions · 2026-05-14: 1Mentions · 2026-06-23: 1Patch / Workaround · 2026-05-12: 3Patch / Workaround · 2026-05-13: 3Patch / Workaround · 2026-05-14: 1Technical Details · 2026-05-10: 2Technical Details · 2026-05-14: 1Technical Details · 2026-06-23: 105-1005-1205-1305-1406-23
Signal classification2 categories
Patch
660.0%
Disclosure
440.0%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-05-102
Disclosure2
2026-05-123
Patch3
2026-05-133
Patch3
2026-05-141
Disclosure1
2026-06-231
Disclosure1
Full discourse10 posts
  • Welsh ICP Conviction 🏴󠁧󠁢󠁷󠁬󠁳󠁿🏉@ICPLEGEND1966
    Disclosure

    🚨 PHP SOAP RCE IS ANOTHER REMINDER WHY OLD INTERNET INFRASTRUCTURE IS BREAKING — AND WHY $ICP BY @dfinity MATTERS ♾️ Another serious server-side vulnerability has landed. This time it is PHP. The critical issue is CVE-2026-6722, a use-after-free vulnerability in the PHP SOAP extension. The risk is not theoretical. A crafted SOAP request can abuse memory handling inside PHP’s XML / SOAP processing and potentially lead to remote code execution. That means a vulnerable server can move from “running an old component” to full compromise. The affected PHP versions are before: • PHP 8.2.31 • PHP 8.3.31 • PHP 8.4.21 • PHP 8.5.6 The PHP changelog also confirms related fixes for: • CVE-2026-6722 — stale SOAP reference / use-after-free • CVE-2026-7261 — SOAP use-after-free after header parsing failure • CVE-2026-7262 — broken Apache map NULL check • Other fixes affecting PHP standard / string handling components This is the same old internet problem. Centralized servers. Legacy runtimes. Patch windows. Exposed endpoints. Misconfigured services. Forgotten extensions. Memory corruption. Emergency updates. Attackers scanning before admins patch. And this is exactly why infrastructure matters. $ICP by @dfinity is not just another blockchain. It is building a different internet architecture where applications can run as canister smart contracts with: • Backend logic on-chain • Frontend assets served on-chain • Data stored on-chain • Identity handled without passwords through Internet Identity • Users not needing gas fees because of reverse gas • Reduced dependence on centralized web servers, exposed APIs, and traditional cloud stacks That does not mean every bug disappears. But it does mean the architecture changes. With ICP, applications are not forced into the same Web2 pattern of: PHP server → database → cloud VM → API keys → DNS → CDN → third-party identity → centralized hosting. That old stack is where many real-world compromises keep happening. PHP SOAP RCE is not just a PHP issue. It is a warning about the fragility of the internet stack most applications still depend on. Crypto keeps arguing about memes, bridges, and token speculation. Meanwhile, the real battle is bigger: Who can build secure, verifiable, tamper-resistant internet infrastructure? That is where $ICP by @dfinity stands apart. Not hype. Not another L1 copy. Not just transactions. A real attempt to rebuild the application layer of the internet itself. The more AI, finance, identity, and enterprise systems move online, the more this matters. Old servers are becoming attack surfaces. ICP is building toward a world where the application itself can become part of the blockchain security model. That is the difference. That is the thesis. That is why I keep saying most people are not bullish enough on $ICP. ♾️ $ICP by @dfinity is not chasing the old internet. It is replacing the broken parts. #ICP #InternetComputer #DFINITY #CyberSecurity #Web3 #Blockchain #OnchainCloud #AI #InfoSec #Crypto Support my independent $ICP research and content: ICP address: 1e672d038cebc619d93186418fa98f6499dbdb9cfdfac54f366c61a4a4ee4362

    Post summary

    The post announces the newly disclosed PHP SOAP use‑after‑free vulnerability (CVE-2026-6722), details affected PHP releases, and notes that patches exist.

    040231647
    1.5K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php83 Module Update 8.3.31-1 https://kusanagi.tokyo/en/releases/24567/ KUSANAGI 9 modules have been updated. The updated modules are as follows: php 8.3.31-1 This update includes support for vulnerability(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261,...

    Post summary

    The post announces a KUSANAGI PHP 8.3 update that patches several CVEs, but provides no PoC, exploit details, or activity reports.

    010101.1K
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php83 モジュール更新情報 8.3.31-1 https://kusanagi.tokyo/releases/24566/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 php 8.3.31-1 この更新には脆弱性(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261, CVE-2026-7262, CVE-2026-7568, CVE-2...

    Post summary

    The kusanagi-php83 module update 8.3.31-1 provides patches for a series of CVEs, fixing multiple vulnerabilities without detailing exploit or technical specifics.

    01010104
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php83 モジュール更新情報 8.3.31-1.el9 https://kusanagi.tokyo/releases/24559/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 php 8.3.31-1.el9 この更新には脆弱性(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261, CVE-2026-7262, CVE-2026-756...

    Post summary

    This post announces a module update that includes patches for multiple CVEs, with no references to exploits or detailed vulnerability data.

    0101099
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php82 モジュール更新情報 8.2.31-1.el9 https://kusanagi.tokyo/releases/24522/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 php 8.2.31-1.el9 この更新には脆弱性(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261, CVE-2026-7262, CVE-2026-756...

    Post summary

    The text announces a KUSANAGI PHP module update that patches multiple CVEs; it does not provide PoC, exploit, or active exploitation details.

    0101094
    200 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The same advisory includes additional SOAP flaws: CVE-2026-7261 (CVSS 6.3): Use-After-Free in SoapServer session persistence CVE-2026-7262 (CVSS 2.9): NULL pointer dereference in Apache Map decoder (DoS)

    Post summary

    The advisory announces two SOAP-related CVEs, providing CVSS scores and brief technical descriptions, but offers no PoC, exploit, active exploitation, or patch information.

    1000039
    295 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php82 Module Update 8.2.31-1 https://kusanagi.tokyo/en/releases/24534/ KUSANAGI 9 modules have been updated. The updated modules are as follows: php 8.2.31-1 This update includes support for vulnerability(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261,...

    Post summary

    The kusanagi‑php82 module update addresses multiple CVEs, but no PoC, exploit code, or evidence of active exploitation is included.

    00000787
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-php82 モジュール更新情報 8.2.31-1 https://kusanagi.tokyo/releases/24533/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 php 8.2.31-1 この更新には脆弱性(CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261, CVE-2026-7262, CVE-2026-7568, CVE-2...

    Post summary

    The release announces a module update for kusanagi‑php82 that includes patches for several CVEs.

    0000070
    200 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7261 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the … https://www.cve.org/CVERecord?id=CVE-2026-7261

    Post summary

    The text announces CVE-2026-7261 affects specific PHP minor releases when SoapServer is set to SOAP_PERSISTENCE_SESSION; it provides affected versions but no exploit, patch, or PoC details.

    00000124
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7261 Use-After-Free in PHP SoapServer With Session Persistence Across Multiple Versions https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7261

    Post summary

    The text announces CVE-2026-7261, a Use‑After‑Free vulnerability affecting PHP SoapServer session persistence across multiple versions, without indicating exploit availability or active attacks.

    0000057
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appphpphp---

Explore more