Three high-severity vulnerabilities have been disclosed in MixPHP Framework versions 2.x through 2.2.17, all tied to unsafe use of PHP unserialize() and carrying potential for remote code execution. CVE-2026-42472 affects Redis-backed session and cache handlers that deserialize data read from Redis, while CVE-2026-42473 impacts FileHandler session and cache logic that deserializes filesystem-sourced data. Both flaws are classified as CWE-502 and were assigned CVSS 3.1 scores reflecting network-exploitable, high-impact risk to confidentiality, integrity, and availability.
A separate issue, CVE-2026-42471, affects the framework’s sync-invoke client, where Connection.php reportedly calls unserialize() on server responses, creating a path to client-side remote code execution if a MixPHP client connects to a malicious server. The three CVEs were published with updated descriptions, references, and severity metadata, highlighting a broader pattern of insecure deserialization across MixPHP components and exposing both server-side and client-side attack surfaces in deployments running vulnerable releases.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
On the same day, the CVE records for CVE-2026-42471, CVE-2026-42472, and CVE-2026-42473 were updated with descriptions, references, CWE-502 classification, and CVSS v3.1 severity information. These updates formalized the technical characterization of the three MixPHP deserialization vulnerabilities.
Details were published for CVE-2026-42472, affecting MixPHP Framework 2.x through 2.2.17, involving unsafe use of PHP unserialize() on Redis-backed session and cache data in RedisHandler. The vulnerability was classified as CWE-502 with a high-severity CVSS v3.1 score vector.
Details were published for CVE-2026-42471, an unsafe deserialization issue in MixPHP Framework 2.x through 2.2.17 where Connection.php unserializes server response data in the sync-invoke client. The issue could allow client-side remote code execution when connecting to a malicious server.
MITRE recorded CVE-2026-42473 affecting MixPHP Framework 2.x through 2.2.17 for unsafe deserialization in FileHandler session and cache handling of filesystem-sourced data. The flaw was described as potentially enabling remote code execution with high impact.
A security disclosure reported six vulnerabilities in MixPHP 2.x through 2.2.17, including four unsafe-deserialization remote code execution flaws and two SQL injection issues affecting query builder functions. The report attributed the findings to Feng Ning of Innora Security Research and described the most severe network-accessible pre-auth deserialization flaw as CVSS 9.8.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcegist.github.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.