CVE-2026-42472

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from Redis in the RedisHandler object.

Published 2026-05-01. Last modified 2026-06-17.