CVE-2026-42473Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from the filesystem in the FileHandler object.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-05-01); latest day: 3
  • 7 total mentions across 3 days

Deep dive

Activity timeline7 mentions / 3d
01223Mentions · 2026-05-01: 3Mentions · 2026-05-04: 1Mentions · 2026-05-13: 3Patch / Workaround · 2026-05-04: 1Technical Details · 2026-05-01: 3Technical Details · 2026-05-04: 1Technical Details · 2026-05-13: 205-0105-0405-13
Signal classification2 categories
Disclosure
685.7%
General
114.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-013
Disclosure3
2026-05-041
Disclosure1
2026-05-133
Disclosure2General1
Full discourse7 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-42473 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17.

    Post summary

    The message announces CVE-2026-42473 as a critical unsafe deserialization flaw in MixPHP Framework, providing CVSS details but no evidence of exploitation or mitigation.

    1000027
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVSS 9.8 CRITICAL · CVE-2026-42473 · 9.8 → 2.2.17 CVE: CVE-2026-42473 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The notice lists CVE‑2026‑42473 with a high CVSS score and severity, but contains no additional details such as PoC, exploit code, active use, or mitigation information.

    1000039
    210 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 critical - MixPHP Unsafe Deserialization (CVE-2026-42473) An unsafe deserialization flaw in MixPHP 2.x through 2.2.17 allows for remote code execution (RCE). The FileHandler object in session and cache handlers processes filesystem data using unserialize(), which can be exploited if an attacker influences the stored data. 👉 Affected: MixPHP 2.x - 2.2.17 | Upgrade to >2.2.17 version

    Post summary

    The post announces a critical unsafe deserialization flaw (CVE‑2026‑42473) in MixPHP 2.x up to 2.2.17 that enables remote code execution, and advises upgrading beyond version 2.2.17.

    0001071
    122 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    https://lyrie.ai/research/research/cve-2026-42473-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The text links to an advisory for CVE‑2026‑42473 but provides no additional details, suggesting an announcement rather than actionable exploit information.

    0000027
    210 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42473 Unsafe Deserialization Vulnerability in MixPHP Framework 2.0 Through 2.2.17 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42473

    Post summary

    The text announces CVE-2026-42473 as an unsafe deserialization vulnerability affecting MixPHP Framework 2.0–2.2.17, with no PoC, exploit code, active exploitation, or patch details mentioned.

    0000042
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-42473 Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from the filesystem in the FileHand… https://www.cve.org/CVERecord?id=CVE-2026-42473 ----- Traducción: CVE-2026-42473 Vul… http://infoflow.cloud`

    Post summary

    This post announces CVE‑2026‑42473, a deserialization flaw in MixPHP Framework, providing basic technical details but no exploit or remediation information.

    0000027
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42473 Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from the filesystem in the FileHand… https://www.cve.org/CVERecord?id=CVE-2026-42473

    Post summary

    The post references CVE‑2026‑42473 and provides a brief technical description of the unsafe deserialization flaw in MixPHP Framework, but does not mention any PoC, exploit, or patch information.

    00000131
    57.4K followersView on X

Explore more