critical CVE-2026-79752
CakePHP is a rapid development framework for PHP: SQL injection possible
NVD (NIST) reports one vulnerability in CakePHP is a rapid development framework for PHP with severity critical. The stated impact is SQL injection. Affected: CVE-2026-79752. The full description, affected versions and recommended action are available from NVD (NIST).
- CVSS
- 9.2
What this means for you
The application can be used to reach the database behind it. Check the logs before you patch: unusual queries suggest the flaw has already been used.
Original source
Insights
More articles
Weekly situation, week 37: 117 advisories, 24 critical
Between 6 Sep and 13 Sep 2026 our sources recorded 117 advisories: 24 critical, 93 high.
Weekly situation, week 36: 55 advisories, 12 critical
Between 30 Aug and 6 Sep 2026 our sources recorded 55 advisories: 12 critical, 43 high.
Weekly situation, week 35: 75 advisories, 21 critical
Between 23 Aug and 30 Aug 2026 our sources recorded 75 advisories: 21 critical, 54 high.
Contact
Reputation takes years. Destruction takes seconds.
Talk to us before somebody else does. The first conversation is free and we reply the same business day.