"It, realistically, requires the combination of an SQL injection flaw with this latest engine bug to do scary damage."

That's the typical MO to exploit a bug, according to Mr. Gibson. There are plenty of partially patched systems and regular findings of squilly injection flaws -

So if you only upgraded to 3.26.0 or not much newer to fix December's injection flaw, you're now vulnerable to both flaws being used as a pair.

