CVE-2026-42472Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from Redis in the RedisHandler object.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-01); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-05-01: 2Mentions · 2026-05-13: 2Technical Details · 2026-05-01: 2Technical Details · 2026-05-13: 105-0105-13
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-012
Disclosure2
2026-05-132
General2
Full discourse4 posts
  • Lyrie.ai@lyrie_ai
    General

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-42472 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post lists CVE-2026-42472 with a high CVSS score and critical severity but provides no details on PoC, exploits, active use, or patches.

    1000031
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-42472-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The supplied text merely references a URL and includes general hashtags, offering no substantive detail about the vulnerability, its exploitation status, or mitigation.

    0000021
    210 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-42472 Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from Redis in the RedisHandler obje… https://www.cve.org/CVERecord?id=CVE-2026-42472 ----- Traducción: CVE-2026-42472 Vul… http://infoflow.cloud`

    Post summary

    The text announces CVE-2026-42472, an unsafe deserialization flaw in MixPHP’s Redis handling, providing technical details but no PoC, exploit, active use, or patch information.

    0000027
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42472 Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from Redis in the RedisHandler obje… https://www.cve.org/CVERecord?id=CVE-2026-42472

    Post summary

    A new CVE (CVE-2026-42472) for MixPHP Framework 2.x identifies unsafe deserialization due to unserialize() on Redis data, with no mention of PoC, exploit, patch, or active exploitation.

    00000125
    57.4K followersView on X

Explore more