CVE-2026-42473
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from the filesystem in the FileHandler object.
Published 2026-05-01. Last modified 2026-06-17.