PULSE
LIVE24signals / 24h
FEED
ransomsafepay reclama a wdk.de · DE · Not Foundransomsafepay reclama a jaecklin-industrial.de · DE · Manufacturingransomsafepay reclama a lbb-treuhand.de · DE · Business Servicesransomsafepay reclama a timetex.de · DE · Business Servicesransomsafepay reclama a stroebel-gruppe.de · DE · Manufacturingransomsafepay reclama a industriesjaro.com · CA · Manufacturingransomsafepay reclama a cenesco.de · DE · Not Foundransomsafepay reclama a acsmallmaxwell.com.au · AU · Business Servicesransomsafepay reclama a mende-grundbesitz.de · DE · Business Servicesransomkairos reclama a College O'Sullivan de Québec · CA · Educationransomkairos reclama a Collge O'Sullivan de Québec · CA · Educationransomincransom reclama a Ali-Monde · US · Not Foundransomcoinbasecartel reclama a Caterpillar · US · Manufacturingransomanubis reclama a Bath Fitter · US · Consumer Servicesransomsafepay reclama a wdk.de · DE · Not Foundransomsafepay reclama a jaecklin-industrial.de · DE · Manufacturingransomsafepay reclama a lbb-treuhand.de · DE · Business Servicesransomsafepay reclama a timetex.de · DE · Business Servicesransomsafepay reclama a stroebel-gruppe.de · DE · Manufacturingransomsafepay reclama a industriesjaro.com · CA · Manufacturingransomsafepay reclama a cenesco.de · DE · Not Foundransomsafepay reclama a acsmallmaxwell.com.au · AU · Business Servicesransomsafepay reclama a mende-grundbesitz.de · DE · Business Servicesransomkairos reclama a College O'Sullivan de Québec · CA · Educationransomkairos reclama a Collge O'Sullivan de Québec · CA · Educationransomincransom reclama a Ali-Monde · US · Not Foundransomcoinbasecartel reclama a Caterpillar · US · Manufacturingransomanubis reclama a Bath Fitter · US · Consumer Services
← All CVEs
CVE WatchJul 8, 2026

CVE-2026-37552

Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke TCP server (Server.php:87) receives data from a TC

CVSS

8.4

High

EPSS

0.3%

p17

KEV

Exploit Today

5

0-100

Published: May 1, 2026 · Last modified: Jul 8, 2026 · CWE-502

EPSS · 30d
0.3%EPSS · 30 days0.3%
2026-06-302026-07-20
Technical description

Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke TCP server (Server.php:87) receives data from a TCP socket, passes it directly to Opis\Closure\unserialize(), then executes the result via call_user_func(). No authentication or signature verification exists on the TCP connection. An attacker with access to the localhost TCP port (server binds 127.0.0.1) can send a crafted serialized PHP closure to achieve arbitrary code execution.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-422379.8 CRI
99.9%
KEV80Sitecore XP Remote Command Execution Vulnerability12d
CVE-2026-456598.8 HIG
86.8%
KEV76Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability19d
CVE-2026-586449.8 CRI
70.8%
KEV71Microsoft SharePoint Deserialization of Untrusted Data Vulnerability4d
CVE-2026-125699.8 CRI
66.0%
KEV70PTC Windchill and FlexPLM Improper Input Validation Vulnerability21d
CVE-2026-505229.8 CRI
97.2%
29Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.6d
CVE-2025-560059.8 CRI
96.7%
29An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile` parameter in the `yacc()` function. This parameter accepts a `.pkl` file that is deserialized with `pickle.load()` without validation. Because `pickle` allows execution of embedded code via `__reduce__()`, an attacker can achieve code execution by passing a malicious pickle file. The parameter is not mentioned in official documentation or the GitHub repository, yet it is active in the PyPI version. This introduces a stealthy backdoor and persistence risk. NOTE: A third-party states that this vulnerability should be rejected because the proof of concept does not demonstrate arbitrary code execution and fails to complete successfully.18h