CVE-2026-37552Disclosure(openmix / mix_php)

LOWCVSS 8.4 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Prioritize remediation for openmix mix_php systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke TCP server (Server.php:87) receives data from a TCP socket, passes it directly to Opis\Closure\unserialize(), then executes the result via call_user_func(). No authentication or signature verification exists on the TCP connection. An attacker with access to the localhost TCP port (server binds 127.0.0.1) can send a crafted serialized PHP closure to achieve arbitrary code execution.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mix_php

Threat summary

  • Active exploitation appears in 1 classified signals
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-05-01); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
mix_php

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-01: 3Mentions · 2026-05-02: 1Active Exploitation · 2026-05-02: 1Technical Details · 2026-05-01: 305-0105-02
Signal classification2 categories
Disclosure
375.0%
Active Exploitation
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-013
Disclosure3
2026-05-021
Active Exploitation1
Full discourse4 posts
  • VulDB 🛡@vuldb
    Active Exploitation

    A lot of offensive activities were identified targeting MixPHP Framework (CVE-2026-37552) https://vuldb.com/vuln/360731/cti

    Post summary

    The post reports that numerous attacks are targeting CVE-2026-37552 in the MixPHP framework, indicating active exploitation in the wild, but provides limited details on the vulnerability or mitigations.

    0101071
    2.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-37552 Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke TCP server (Server.php:87) receives data from a TCP socket, passes it direct… https://www.cve.org/CVERecord?id=CVE-2026-37552

    Post summary

    The passage announces a new CVE‑2026‑37552, describing an unsafe deserialization flaw in MixPHP Framework 2.x through 2.2.17, but provides no PoC, exploit code, or evidence of active exploitation.

    00010146
    57.4K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-37552 Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke TCP server (Server.php:87) receives data from a TCP socket, passes it direct… https://www.cve.org/CVERecord?id=CVE-2026-37552 ----- Traducción: CVE-2026-37552 Vul… http://infoflow.cloud`

    Post summary

    A new unsafe deserialization vulnerability (CVE-2026-37552) in MixPHP Framework 2.x has been announced; while the CVE record is linked, there is no evidence of exploitation, PoC, or patches in this notice.

    0000024
    75 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-37552 Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke TCP server (Server.php:87) re… CVSS 8.4 Full analysis → https://sec.kaitan.id/cves/CVE-2026-37552 #HP #CyberSecurity #InfoSec

    Post summary

    The tweet announces a high‑severity unsafe deserialization vulnerability (CVE‑2026‑37552) in MixPHP Framework 2.x, noting a CVSS score of 8.4, but offers no PoC, exploit code, active exploitation evidence, or patch information.

    0000038
    459 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenmixmix_php---

Explore more