critical CVE-2026-79752
CakePHP is a rapid development framework for PHP: SQL injection possible
NVD (NIST) reports one vulnerability in CakePHP is a rapid development framework for PHP with severity critical. The stated impact is SQL injection. Affected: CVE-2026-79752. The full description, affected versions and recommended action are available from NVD (NIST).
- CVSS
- 9.2
What this means for you
The application can be used to reach the database behind it. Check the logs before you patch: unusual queries suggest the flaw has already been used.
Original source
Insights
More articles
Weekly situation, week 39: 83 advisories, 22 critical
Between 20 Sep and 27 Sep 2026 our sources recorded 83 advisories: 22 critical, 61 high.
Weekly situation, week 38: 108 advisories, 26 critical
Between 13 Sep and 20 Sep 2026 our sources recorded 108 advisories: 26 critical, 82 high.
Weekly situation, week 37: 117 advisories, 24 critical
Between 6 Sep and 13 Sep 2026 our sources recorded 117 advisories: 24 critical, 93 high.
Contact
Reputation takes years. Destruction takes seconds.
Talk to us before somebody else does. The first conversation is free and we reply the same business day.