These are the security fixes as shown in the current changelog at:

I chased down the CVS commit log messages against 5_2 for each of these.
Most of the fixes look relatively compact, with the exception of the
last, which is comparatively huge.

Version 5.2.6
      * Security Fixes
              * Fixed possible stack buffer overflow in FastCGI SAPI.
                (Andrei Nigmatulin)
              * Properly address incomplete multibyte chars inside
                escapeshellcmd() (Ilia, Stefan Esser)
              * Fixed security issue detailed in CVE-2008-0599. (Rasmus)
              * Fixed a safe_mode bypass in cURL identified by
                Maksymilian Arciemowicz. (Ilia)
              * Upgraded PCRE to version 7.6 (Nuno)
                      * Note, this is a very LARGE patch